<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM in Cisco 6500 - High CPU usage in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375788#M797160</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your ACLs size is big. more than 50K rules for example, this is probably normal.&lt;/P&gt;&lt;P&gt;Especially if you also have ACL optimization on.&lt;/P&gt;&lt;P&gt;In general is it normal to see your CPU go to 80-90% and the time depend on ACL size and optimization.&lt;/P&gt;&lt;P&gt;The 90% should yield to other processes so it should not interrupt traffic. And also, while the new ACL is compiled the old ACL is backed up in a special ACL partition and it is the ACL still used before the new ACL is compiled and put into action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Nov 2010 13:59:11 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2010-11-24T13:59:11Z</dc:date>
    <item>
      <title>FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375783#M797155</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;We have a Cisco Catalyst 6500 with a FWSM running V 4.0(6)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have noticed that when we apply new rules into the ACL (through ASDM or CLI) that after the ACL is applied,&lt;/P&gt;&lt;P&gt;the CPU sits very high (90-100%) for up to 20 min.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During this time, the new rules you have entered into the ACL, do not work, until the CPU drops back to normal baseline usage which is about 10%, after about 20 min or so...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at CPUHOG during this time, doesnt give us an indication about what is happening..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dion&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375783#M797155</guid>
      <dc:creator>dneggers1</dc:creator>
      <dc:date>2019-03-11T17:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375784#M797156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep in mind that if you ACL is big and if you have ACL optimization enabled the CPU could spike up to 10-15 minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also note bug "CSCta62033: Adding remark lines to an optimized ACL can trigger prolonged high CPU" that is fixed in 4.0.7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2010 20:32:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375784#M797156</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-03-16T20:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375785#M797157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However we are not using ACL optimisation..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could this occur without Optimisation turned on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dion&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2010 20:53:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375785#M797157</guid>
      <dc:creator>dneggers1</dc:creator>
      <dc:date>2010-03-16T20:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375786#M797158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, 20 mins is a little high. Up to 10 depending on traffic could be normal.&lt;/P&gt;&lt;P&gt;It could also be the bug I mentioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Mar 2010 00:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375786#M797158</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-03-17T00:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375787#M797159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we use a FWSM cluster in 6k5 with Sup720, too.&lt;/P&gt;&lt;P&gt;Software version is 4.0(12).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We see the same, changing one ACL results in having CPU of 90% over nearly 10 minutes.&lt;/P&gt;&lt;P&gt;For that time the new ACL is not active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there some new information about that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Nov 2010 13:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375787#M797159</guid>
      <dc:creator>Sven Hruza</dc:creator>
      <dc:date>2010-11-24T13:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375788#M797160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your ACLs size is big. more than 50K rules for example, this is probably normal.&lt;/P&gt;&lt;P&gt;Especially if you also have ACL optimization on.&lt;/P&gt;&lt;P&gt;In general is it normal to see your CPU go to 80-90% and the time depend on ACL size and optimization.&lt;/P&gt;&lt;P&gt;The 90% should yield to other processes so it should not interrupt traffic. And also, while the new ACL is compiled the old ACL is backed up in a special ACL partition and it is the ACL still used before the new ACL is compiled and put into action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Nov 2010 13:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375788#M797160</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-11-24T13:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375789#M797161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot for the reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I think we have something about 65k of rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see that in the output of sh np 3 acl count 0, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;-------------- CLS Rule Current Counts --------------&lt;BR /&gt;CLS Filter Rule Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;CLS Fixup Rule Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5621&lt;BR /&gt;CLS Est Ctl Rule Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;CLS AAA Rule Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;CLS Est Data Rule Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;CLS Console Rule Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 58&lt;BR /&gt;CLS Policy NAT Rule Count&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&lt;STRONG&gt;CLS ACL Rule Count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65493&lt;/STRONG&gt;&lt;BR /&gt;CLS ACL Uncommitted Add&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;CLS ACL Uncommitted Del&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;---------------- CLS Rule MAX Counts ----------------&lt;BR /&gt;CLS Filter MAX&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3747&lt;BR /&gt;CLS Fixup MAX&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5621&lt;BR /&gt;CLS Est Ctl Rule MAX&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 624&lt;BR /&gt;CLS Est Data Rule MAX&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 624&lt;BR /&gt;CLS AAA Rule MAX&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8744&lt;BR /&gt;CLS Console Rule MAX&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2498&lt;BR /&gt;CLS Policy NAT Rule MAX&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2498&lt;BR /&gt;&lt;STRONG&gt;CLS ACL Rule MAX&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100567&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And is it right that the max number of ACL is 100567 for the system? What will happen if we get more than those ACLs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Nov 2010 08:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375789#M797161</guid>
      <dc:creator>Sven Hruza</dc:creator>
      <dc:date>2010-11-25T08:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375790#M797162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep, you seem to have many ACL rules, so the compilation will take a few minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you reach the 100K limit then the FWSM will not let you add more rules and it will give you an error when you add a rule saying "ACL rule limit reached".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 16:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375790#M797162</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-11-26T16:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375791#M797163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Here is a nice document that I wrote on FWSM acl limit: &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-8786"&gt;https://supportforums.cisco.com/docs/DOC-8786&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 19:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375791#M797163</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-11-26T19:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375792#M797164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot for the repsonses and the link to your documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try to reduce the number of ACLs and objects on my FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Nov 2010 15:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375792#M797164</guid>
      <dc:creator>Sven Hruza</dc:creator>
      <dc:date>2010-11-27T15:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375793#M797165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad we could help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take care,&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Nov 2010 17:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375793#M797165</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-11-28T17:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375794#M797166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can enable ACL optimization , which will reduce the number of ACLs, and the FWSM will keep the optimized configuration separate than the normal running configuration. Then copy the optimized running configuration in to the running configuration using the command "copy optimized-running-config running-config" will replace the existing running configuration with the optimized one. using this you will be able to reduce the number of ACLs and there by increasing the FWSM performance. Please let me know once you done.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Jan 2011 09:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375794#M797166</guid>
      <dc:creator>sudheesh.pb</dc:creator>
      <dc:date>2011-01-01T09:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375795#M797167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for that hint, sudheesh.ph.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that ACL optimization is only for finding double ACLs in the configuration.&lt;/P&gt;&lt;P&gt;Or is there something else the optimization will do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is not easy to activate the optimization because the FWSM is very important for our production.&lt;/P&gt;&lt;P&gt;So I can't try that in the next time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I activate that but get my "normal" config running?&lt;/P&gt;&lt;P&gt;I want to check out the differences between normal and optimized config.&lt;/P&gt;&lt;P&gt;I thought by activating the optimization in ASDM and apply it, it will get active in the running-config and is productive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jan 2011 10:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375795#M797167</guid>
      <dc:creator>Sven Hruza</dc:creator>
      <dc:date>2011-01-03T10:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in Cisco 6500 - High CPU usage</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375796#M797168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL optimization will find the double entries and it will try to combine the rules if possible. you will be able to see minimum of a 60% reduction in the ACLs after enabling optimization. There is no issues on doing this exercise on a production blade, as normally it will not impact the usual traffic and sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN&gt;The fwsm keeps the original ACL in the configuration for user convenience. However, the version &lt;/SPAN&gt;&lt;SPAN&gt;that is compiled into the hardware is the ACL displayed through the “show access-list optimization” &lt;/SPAN&gt;&lt;SPAN&gt;command. Therefore, after entering the “access-list optimization enable” command, you will see &lt;/SPAN&gt;&lt;SPAN&gt;two ACLs present in the configuration. Modifications are always made to the original ACL, and the &lt;/SPAN&gt;&lt;SPAN&gt;optimization process runs its course using the new changes. Users cannot directly modify the &lt;/SPAN&gt;&lt;SPAN&gt;optimized version of the ACL. So it is possible for you to compare both the configurations.&amp;nbsp; rank me if this information helps you.. &lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="font-family: Arial; font-size: 8pt;"&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Sudheesh&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jan 2011 20:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-cisco-6500-high-cpu-usage/m-p/1375796#M797168</guid>
      <dc:creator>sudheesh.pb</dc:creator>
      <dc:date>2011-01-04T20:37:08Z</dc:date>
    </item>
  </channel>
</rss>

