<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM performance issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354874#M754048</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Hi Madhu,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Even we faced the same issue on our one of the telecom customer in India.Whenever we will apply ACL , then CPU used to go around 95% and lots of latency.so we have decided do change the architecture.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;If you have multiple L3 interfaces defined in FWSM that might be the one of the cause..because in this scenario the FWSM has to do routing and since all the L3 definition is in FWSM there will be lots of ARP entries.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;In our scenario we have contacted cisco TAC, they suggest to one option is to remove all the L3 defintion in FWSM and change to SW ( restructuring the network) and another way is that upgrade the IOS into 4.1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;We have selected the first option .Now no more performance issue with FWSM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Later ACL is reached the 10K, then we have upgraded IOS into 4.1 version and we have enabled ACL optimization.Now everything is going fine....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Hope it Helps..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&lt;STRONG&gt;Karuppuchamy CCIE(R&amp;amp;S),CCSP&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Jan 2010 07:19:08 GMT</pubDate>
    <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
    <dc:date>2010-01-12T07:19:08Z</dc:date>
    <item>
      <title>FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354873#M754036</link>
      <description>&lt;P&gt;&lt;SPAN style="color: #5f5f5f; font-family: Tms Rmn; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;Hi all,&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;SPAN style="color: #5f5f5f; font-family: Courier; "&gt;Our customer's Datacentre live on Saturday. Since then we have faced major performance issue in FWSM. The latency jumps up whenever we access the CLI or add any entries to the device. The memory utilization is already 49% even though we have placed only 1000 ACL entries as of now.customer suspect major performance degradation once Full Load is there on the Device. customer have around 10,000 ACL entries to be added. kindly suggets&lt;/SPAN&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;SPAN style="color: #5f5f5f; font-family: Courier; "&gt;regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;SPAN style="color: #5f5f5f; font-family: Courier;"&gt;&lt;SPAN style="color: #5f5f5f; font-family: Courier;"&gt;Madhu&lt;SPAN style=": ; font-family: Courier; font-color: #5f5f5f; "&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;SPAN style="font-color: #5f5f5f; font-family: Courier; "&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;attached the logs and sh version output.&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;============================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;SPAN style="color: #5f5f5f; font-family: Courier; "&gt;&lt;P dir="ltr"&gt;sh ver&lt;/P&gt;&lt;P dir="ltr"&gt;FWSM Firewall Version 3.1(10)&lt;/P&gt;&lt;P dir="ltr"&gt;Device Manager Version 6.1(5)F&lt;/P&gt;&lt;P dir="ltr"&gt;Compiled on Mon 21-Apr-08 17:43 by fwsmbld&lt;/P&gt;&lt;P dir="ltr"&gt;Religare-FWSM up 2 days 11 hours&lt;/P&gt;&lt;P dir="ltr"&gt;failover cluster up 2 days 11 hours&lt;/P&gt;&lt;P dir="ltr"&gt;Hardware: WS-SVC-FWM-1, 1024 MB RAM, CPU Pentium III 1000 MHz&lt;/P&gt;&lt;P dir="ltr"&gt;Flash STI Flash 8.0.0 @ 0xc321, 20MB&lt;/P&gt;&lt;P dir="ltr"&gt;0: Int: Not licensed : irq 5&lt;/P&gt;&lt;P dir="ltr"&gt;1: Int: Not licensed : irq 7&lt;/P&gt;&lt;P dir="ltr"&gt;2: Int: Not licensed : irq 11&lt;/P&gt;&lt;P dir="ltr"&gt;The Running Activation Key is not set, using default settings:&lt;/P&gt;&lt;P dir="ltr"&gt;Licensed features for this platform:&lt;/P&gt;&lt;P dir="ltr"&gt;Maximum Interfaces : 256&lt;/P&gt;&lt;P dir="ltr"&gt;Inside Hosts : Unlimited&lt;/P&gt;&lt;P dir="ltr"&gt;Failover : Active/Active&lt;/P&gt;&lt;P dir="ltr"&gt;VPN-DES : Enabled&lt;/P&gt;&lt;P dir="ltr"&gt;VPN-3DES-AES : Enabled&lt;/P&gt;&lt;P dir="ltr"&gt;Cut-through Proxy : Enabled&lt;/P&gt;&lt;P dir="ltr"&gt;Guards : Enabled&lt;/P&gt;&lt;P dir="ltr"&gt;URL Filtering : Enabled&lt;/P&gt;&lt;P dir="ltr"&gt;Security Contexts : 2&lt;/P&gt;&lt;P dir="ltr"&gt;GTP/GPRS : Disabled&lt;/P&gt;&lt;P dir="ltr"&gt;VPN Peers : Unlimited&lt;/P&gt;&lt;P dir="ltr"&gt;Serial Number: SAD125004FT&lt;/P&gt;&lt;P dir="ltr"&gt;Running Activation Key: 0x00000000 0x00000000 0x00000000 0x00000000&lt;/P&gt;&lt;P dir="ltr"&gt;Configuration last modified by enable_15 at 14:41:28.611 IST Mon Jan 11&lt;/P&gt;&lt;P dir="ltr"&gt;2010&lt;/P&gt;&lt;/SPAN&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;P&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;============================================&lt;/P&gt;&lt;P dir="ltr"&gt;Sh logging&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;P dir="ltr"&gt;sh lof&amp;nbsp;&amp;nbsp; gg &lt;/P&gt;&lt;P dir="ltr"&gt;FWSM-Switch-Primary&amp;gt;sh loggi &lt;/P&gt;&lt;P dir="ltr"&gt;FWSM-Switch-Primary&amp;gt;sh loggi&lt;/P&gt;&lt;P dir="ltr"&gt;Syslog logging: enabled (0 messages dropped, 0 messages rate-limited, 0 flushes, 0 overruns, xml disabled, filtering disabled)&lt;/P&gt;&lt;P dir="ltr"&gt;Console logging: level debugging, 92 messages logged, xml disabled,&lt;/P&gt;&lt;P dir="ltr"&gt;filtering disabled&lt;/P&gt;&lt;P dir="ltr"&gt;Monitor logging: level debugging, 0 messages logged, xml disabled,&lt;/P&gt;&lt;P dir="ltr"&gt;filtering disabled&lt;/P&gt;&lt;P dir="ltr"&gt;Buffer logging: level debugging, 92 messages logged, xml disabled,&lt;/P&gt;&lt;P dir="ltr"&gt;filtering disabled&lt;/P&gt;&lt;P dir="ltr"&gt;Exception Logging: size (4096 bytes)&lt;/P&gt;&lt;P dir="ltr"&gt;Count and timestamp logging messages: disabled&lt;/P&gt;&lt;P dir="ltr"&gt;Trap logging: level informational, 110 message lines logged&lt;/P&gt;&lt;P dir="ltr"&gt;Logging to 10.216.16.60, 110 message lines logged, xml disabled,&lt;/P&gt;&lt;P dir="ltr"&gt;filtering disabled&lt;/P&gt;&lt;P dir="ltr"&gt;--More--&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P dir="ltr"&gt;Log Buffer (16384 bytes):&lt;/P&gt;&lt;P dir="ltr"&gt;00:01:35: curr is 0x0&lt;/P&gt;&lt;P dir="ltr"&gt;00:01:35: RP: Currently running ROMMON from S (Gold) region&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:14:14 IST: %SYS-6-CLOCKUPDATE: System clock has been updated from 21:44:14 UTC Fri Jan 8 2010 to 03:14:14 IST Sat Jan 9 2010, configured from console by console.&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:14:17 IST: %SYS-5-CONFIG_I: Configured from memory by console&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:14:20 IST: %SYS-5-RESTART: System restarted --&lt;/P&gt;&lt;P dir="ltr"&gt;Cisco IOS Software, s72033_rp Software (s72033_rp-ADVIPSERVICESK9_WAN-M), Version 12.2(33)SXH4, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P dir="ltr"&gt;Technical Support:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN style="color: #5f5f5f; font-family: Tms Rmn; "&gt;&lt;P dir="ltr"&gt;Copyright (c) 1986-2008 by Cisco Systems, Inc.&lt;/P&gt;&lt;P dir="ltr"&gt;Compiled Mon 10-Nov-08 07:00 by prod_rel_team&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:14:20 IST: %NTP-6-RESTART: NTP process starts&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:14:20 IST: %SNMP-5-COLDSTART: SNMP agent on host FWSM-Switch-Primary is undergoing a cold start&lt;/P&gt;&lt;P dir="ltr"&gt;00:00:08: %SYS-SP-3-LOGGER_FLUSHED: System was paused for 00:00:00 to ensure console debugging output.&lt;/P&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;SPAN style="color: #5f5f5f; font-family: Tms Rmn; "&gt;&lt;P dir="ltr"&gt;*Jan 9 03:15:36 IST: %SNMP-5-MODULETRAP: Module 2 [Up] Trap&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:15:36 IST: %OIR-SP-6-INSCARD: Card inserted in slot 2, interfaces are now online&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:15:39 IST: %SVCLC-5-FWTRUNK: Firewalled VLANs configured on trunks&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:15:45 IST: %DIAG-SP-6-DIAG_OK: Module 1: Passed Online Diagnostics&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:15:50 IST: %FABRIC-SP-5-CLEAR_BLOCK: Clear block option is off for the fabric in slot 6.&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:15:50 IST: %FABRIC-SP-5-FABRIC_MODULE_BACKUP: The Switch Fabric Module in slot 6 became standby&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:15:56 IST: %SNMP-5-MODULETRAP: Module 1 [Up] Trap&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:15:56 IST: %OIR-SP-6-INSCARD: Card inserted in slot 1, interfaces are now online&lt;/P&gt;&lt;P dir="ltr"&gt;--More--&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Jan 9 03:16:02 IST: %DIAG-SP-6-RUN_MINIMUM: Module 6: Running Minimal Diagnostics...&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:16:03 IST: %DIAG-SP-6-DIAG_OK: Module 6: Passed Online Diagnostics&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:16:05 IST: %SNMP-5-MODULETRAP: Module 6 [Up] Trap&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:16:05 IST: %OIR-SP-6-INSCARD: Card inserted in slot 6, interfaces are now online&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:16:10 IST: %DIAG-SP-6-RUN_MINIMUM: Module 3: Running Minimal Diagnostics...&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:16:13 IST: %SVCLC-5-FWVTPMODE: VTP mode is set to non-transparent&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:16:13 IST: %MFIB_CONST_RP-6-REPLICATION_MODE_CHANGE: Replication Mode Change Detected. Current system replication mode is Ingress&lt;/P&gt;&lt;P dir="ltr"&gt;*Jan 9 03:16:13 IST: %SNMP-5-MODULETRAP: Module 3 [Up] Trap&lt;/P&gt;&lt;P dir="ltr"&gt;Jan 9 03:16:13 IST: %DIAG-SP-6-DIAG_OK: Module 3: Passed Online Diagnostics&lt;/P&gt;&lt;P dir="ltr"&gt;00:02:48: %SYS-SPSTBY-3-LOGGER_FLUSHED: System was paused for 00:00:00 to ensure console debugging output.&lt;/P&gt;&lt;P dir="ltr"&gt;00:03:15: SPSTBY: SP: Currently running ROMMON from S (Gold) region&lt;/P&gt;&lt;P dir="ltr"&gt;00:03:20: %DIAG-SPSTBY-6-RUN_MINIMUM: Module 6: Running Minimal Diagnostics...&lt;/P&gt;&lt;P dir="ltr"&gt;00:03:28: %DIAG-SPSTBY-6-DIAG_OK: Module 6: Passed Online Diagnostics&lt;/P&gt;&lt;P dir="ltr"&gt;00:03:48: %SYS-SPSTBY-5-RESTART: System restarted --&lt;/P&gt;&lt;P dir="ltr"&gt;Cisco IOS Software, s72033_sp Software (s72033_sp-ADVIPSERVICESK9_WAN-M), Version 12.2(33)SXH4, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P dir="ltr"&gt;Technical Support:&lt;/P&gt;&lt;/SPAN&gt;&lt;P dir="ltr"&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354873#M754036</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2019-03-11T16:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354874#M754048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Hi Madhu,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Even we faced the same issue on our one of the telecom customer in India.Whenever we will apply ACL , then CPU used to go around 95% and lots of latency.so we have decided do change the architecture.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;If you have multiple L3 interfaces defined in FWSM that might be the one of the cause..because in this scenario the FWSM has to do routing and since all the L3 definition is in FWSM there will be lots of ARP entries.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;In our scenario we have contacted cisco TAC, they suggest to one option is to remove all the L3 defintion in FWSM and change to SW ( restructuring the network) and another way is that upgrade the IOS into 4.1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;We have selected the first option .Now no more performance issue with FWSM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Later ACL is reached the 10K, then we have upgraded IOS into 4.1 version and we have enabled ACL optimization.Now everything is going fine....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma,arial,helvetica,sans-serif;"&gt;Hope it Helps..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&lt;STRONG&gt;Karuppuchamy CCIE(R&amp;amp;S),CCSP&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 07:19:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354874#M754048</guid>
      <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
      <dc:date>2010-01-12T07:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354875#M754088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&lt;STRONG&gt;Hi Karuppuchamy,&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;&lt;EM&gt;I could not find the sw version 4.1, only 4.0(9) is the latest version available. if you can send me the link it will be very helpfull for me.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;&lt;EM&gt;Thanks &amp;amp; regards&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;&lt;EM&gt;Madhu&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 09:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354875#M754088</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2010-01-12T09:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354876#M754120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sorry...and we running 4.0(7).Please find the FWSM sh version details.....hope it helps u....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="salutation"&gt;&lt;/SPAN&gt;ITServerFW# sh version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM&amp;nbsp; Firewall Version 4.0(7)&lt;BR /&gt;Device Manager Version 6.0(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Tue&amp;nbsp; 08-Sep-09 20:48 by fwsmbld&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ITServerFW up 115 days 14 hours&lt;BR /&gt;failover&amp;nbsp; cluster up 301 days 0 hours&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware: WS-SVC-FWM-1, 1024 MB RAM, CPU&amp;nbsp; Pentium III 1000 MHz&lt;BR /&gt;Flash STI Flash 8.0.0 @ 0xc321, 20MB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0: Int:&amp;nbsp; GigabitEthernet0 : address is 0023.336a.dd00, irq 5&lt;BR /&gt;1: Int: GigabitEthernet1&amp;nbsp; : address is 0023.336a.dd00, irq 7&lt;BR /&gt;2: Int: EOBC0 : address is 0000.1100.0000,&amp;nbsp; irq 11&lt;BR /&gt;The Running Activation Key is not set, using default&amp;nbsp; settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Interfaces :&amp;nbsp; 256&lt;BR /&gt;Inside Hosts : Unlimited&lt;BR /&gt;Failover : Active/Active&lt;BR /&gt;VPN-DES :&amp;nbsp; Enabled&lt;BR /&gt;VPN-3DES-AES : Enabled&lt;BR /&gt;Cut-through Proxy : Enabled&lt;BR /&gt;Guards :&amp;nbsp; Enabled&lt;BR /&gt;URL Filtering : Enabled&lt;BR /&gt;Security Contexts : 2&lt;BR /&gt;GTP/GPRS :&amp;nbsp; Disabled&lt;BR /&gt;BGP Stub : Disabled&lt;BR /&gt;Service Acceleration : Disabled&lt;BR /&gt;VPN Peers&amp;nbsp; : Unlimited&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 09:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354876#M754120</guid>
      <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
      <dc:date>2010-01-12T09:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354877#M754150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the suggestion, since you worked with TAC in this issue, I have few queries i would like to ask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What all thing we can check to confirm that the latancy and the high utilization is due to the L3 defination in FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the back plane capacity for FWSM? i thing not sure but 60GB, isn't it enough to take the load(arp request and routing etc) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to justify my suggestion to our customer, Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Madhu &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 10:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354877#M754150</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2010-01-12T10:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354878#M754178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I am planning to upgrade the image from 3.1(10) to 4.0.(8), My question is whether i can directly upgrade from 3.1(10) to 4.0(8) or i need to upgrade to 4.0 then 4.0(8).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Madhu&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 14:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354878#M754178</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2010-01-12T14:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354879#M754200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Madhu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer your last question, you can upgrade from 3.1 to 4.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you have downtime though and if you have failover that the FWSMs are not running 3.1 and 4.0 at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jan 2010 21:15:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354879#M754200</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-01-12T21:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354880#M754219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you guys for the help..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have sceduled for upgrading the FWSM by this weekend hope this will hepl in resolving the performance issue and other memory related issue which is faced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 04:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354880#M754219</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2010-01-13T04:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354881#M754232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Madhu,&lt;/P&gt;&lt;P&gt;Did the upgrade solve your issue?&lt;/P&gt;&lt;P&gt;We are facing a similar problem with our FWSM 4.0(4) and we are planning an upgrade to 4.0(9) to see if this will mitigate our issue.&lt;/P&gt;&lt;P&gt;Let me know&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Carlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jan 2010 04:30:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354881#M754232</guid>
      <dc:creator>Carlo Poggiarelli</dc:creator>
      <dc:date>2010-01-21T04:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM performance issue</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354882#M754246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it has helped me as i have upgraded from 3.1.10 to 4.0.8, so there are some ACL inhancement in new version when comparing with 3.x. Not sure how effective it would be for you as you will be upgrading the same(4.0.4 to 4.0.9) , may be some bug might have fixed in the latest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 10:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-performance-issue/m-p/1354882#M754246</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2010-01-22T10:13:07Z</dc:date>
    </item>
  </channel>
</rss>

