<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 100% Sensor load during some period in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299378#M68385</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May be there are lot of small packets going through the sensor.&lt;/P&gt;&lt;P&gt;Activate flood-signatures and analyze alerts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Nov 2009 08:40:24 GMT</pubDate>
    <dc:creator>andrey.dugin</dc:creator>
    <dc:date>2009-11-06T08:40:24Z</dc:date>
    <item>
      <title>100% Sensor load during some period</title>
      <link>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299374#M68367</link>
      <description>&lt;P&gt;Dear ALL,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue: IDSM is showing 100% Inspection(Sensor) Load during certain periods daily which causes more than 2000 ms delay in the network.This issue occurs after upgrading the signature engine to E3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have also monitored the traffic during 100% Load on PRTG but traffic has still in normal utilization 40 to 50Mb.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found the same 100% Load issue on the Cisco TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has any one faced this issue before in their workaround. Actually we are not sure about our issue. Is our issue also related to SMTP traffic or not as in the TAC case.&lt;/P&gt;&lt;P&gt;How can we identify our issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the following TAC case:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Symptom:&lt;/P&gt;&lt;P&gt;IDSM is showing high CPU and a "processing load percentage" of 100 during certain periods daily. Traffic is affected at those times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;/P&gt;&lt;P&gt;Issue has been identified to be linked to smtp traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsz81580&amp;amp;from=summary" target="_blank"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsz81580&amp;amp;from=summary&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we solve/identify this issue? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please provide us the appropriate solution for this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the details of IDSM-2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our IDSM is in Inline VLAN-Pair Mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inline TCP Tracking Mode: Interface and VLAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core Switch IPS Etherchannel Setup:&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 5: IDSM(A) and IDSM(B) Port x/7&lt;/P&gt;&lt;P&gt;Group 6: IDSM(A) and IDSM(B) Port x/8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some VLAN Pair(s) are on interface x/7 and others are on x/8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an FWSM module also, which acts as the default gateway for all internal VLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All signatures are in default state.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS1 version Detail:&lt;/P&gt;&lt;P&gt;Cisco Intrusion Prevention System, Version 6.1(2)E3&lt;/P&gt;&lt;P&gt;Signature Update S440.0&lt;/P&gt;&lt;P&gt;OS Version:2.4.30-IDS-smp-bigphys&lt;/P&gt;&lt;P&gt;Platform:WS-SVC-IDSM-2&lt;/P&gt;&lt;P&gt;Cisco6513 IOS: Version 12.2(18)SXF17 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anser&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299374#M68367</guid>
      <dc:creator>Muhammad Anser Khan</dc:creator>
      <dc:date>2019-03-10T11:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: 100% Sensor load during some period</title>
      <link>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299375#M68372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't say how much traffic you are trying to push through that IDSM, but if you overload it, you will get delay and lost packets.&lt;/P&gt;&lt;P&gt;You can try putting the sensor into promisicous mode and doing shunning on the FWSM. That way, no matter how badly the sensor performs, you will not distrupt traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 16:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299375#M68372</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-10-26T16:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: 100% Sensor load during some period</title>
      <link>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299376#M68377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not a traffic issue. Traffic shows very low during 100% sensor load.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anser&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Oct 2009 05:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299376#M68377</guid>
      <dc:creator>Muhammad Anser Khan</dc:creator>
      <dc:date>2009-10-27T05:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: 100% Sensor load during some period</title>
      <link>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299377#M68380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I get "Red" status events on "inspectionLoad" very frequently.  I am not quite sure if it has always been this frequent.  I wonder if the "healthAndSecurity" status alerts can be sent off to a syslog server for long term storage, review and analysis.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you getting "Red" status events on "inspectionLoad"?  Just recently or all the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is another thread in this forum about something like highcpu or something like that.  I am not sure if that one was very specific.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if this is related to Cisco updating signature files with new sigs are enabled by default related to 5 year old vulnerabilities.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evStatus: eventId=REMOVED&lt;/P&gt;&lt;P&gt;vendor=Cisco  &lt;/P&gt;&lt;P&gt;  originator:   &lt;/P&gt;&lt;P&gt;    hostId: REMOVED  &lt;/P&gt;&lt;P&gt;    appName: monitor  &lt;/P&gt;&lt;P&gt;    appInstanceId: 345  &lt;/P&gt;&lt;P&gt;  time: Nov 03, 2009 19:08:51 UTC  offset=-300  timeZone=EST  &lt;/P&gt;&lt;P&gt;  healthAndSecurity:   &lt;/P&gt;&lt;P&gt;    description: Health and security status  &lt;/P&gt;&lt;P&gt;    healthStatus: red  &lt;/P&gt;&lt;P&gt;    securityStatus:   &lt;/P&gt;&lt;P&gt;      virtualSensor: vs0  &lt;/P&gt;&lt;P&gt;      status: green  &lt;/P&gt;&lt;P&gt;    changed:   &lt;/P&gt;&lt;P&gt;      metricValue:   name=inspectionLoad  &lt;/P&gt;&lt;P&gt;        current:   &lt;/P&gt;&lt;P&gt;          value: 94  &lt;/P&gt;&lt;P&gt;          status: red  &lt;/P&gt;&lt;P&gt;        previous:   &lt;/P&gt;&lt;P&gt;          value: 17  &lt;/P&gt;&lt;P&gt;          status: green  &lt;/P&gt;&lt;P&gt;        thresholds:   &lt;/P&gt;&lt;P&gt;          type: upper  &lt;/P&gt;&lt;P&gt;          yellow: 80  &lt;/P&gt;&lt;P&gt;          red: 91  &lt;/P&gt;&lt;P&gt;    warning:   &lt;/P&gt;&lt;P&gt;      metricStatus:   name=inspectionLoad  &lt;/P&gt;&lt;P&gt;        status: red  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Nov 2009 20:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299377#M68380</guid>
      <dc:creator>bnidacoc</dc:creator>
      <dc:date>2009-11-03T20:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: 100% Sensor load during some period</title>
      <link>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299378#M68385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May be there are lot of small packets going through the sensor.&lt;/P&gt;&lt;P&gt;Activate flood-signatures and analyze alerts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 08:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/100-sensor-load-during-some-period/m-p/1299378#M68385</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2009-11-06T08:40:24Z</dc:date>
    </item>
  </channel>
</rss>

