<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: C2821 CPU overload in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102138#M914394</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try checking the CPU load during low volume and high volume times. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show proc cpu | e 0.00%  0.00%  0.00%&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think you'll get a definitive answer but it should help point in the right direction. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check this-&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_0t/12_0t4/feature/guide/fw800.html#wp20431" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_0t/12_0t4/feature/guide/fw800.html#wp20431&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CBAC was designed for SMBs, not really Enterprises. I understand that routers work better (and I usually suggest them to my customers), but you might have to figure out new routing techniques and put in a ASA firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Aug 2008 16:16:07 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2008-08-18T16:16:07Z</dc:date>
    <item>
      <title>C2821 CPU overload</title>
      <link>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102137#M914393</link>
      <description>&lt;P&gt;I use a 2821 IOSFW for internet access&lt;/P&gt;&lt;P&gt;It holds 14 DMZ (one Vlan / server on each)&lt;/P&gt;&lt;P&gt;and about 2000 internal internet daily users.&lt;/P&gt;&lt;P&gt;My internet access is 10Mbps symetric.&lt;/P&gt;&lt;P&gt;When trafic grows, CPU grows correspondingly to IP trafic, up to 50%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose that CPU load is due to IP nat,  ACLs and CBAC between inside and outside.&lt;/P&gt;&lt;P&gt;Some external Citrix users sometimes loose their connexion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco's Commercial argue that I should migrate to ASA 5510, but I need some features like PBR which is unavailable.&lt;/P&gt;&lt;P&gt;I am looking for a serious diagnostic method.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102137#M914393</guid>
      <dc:creator>falain</dc:creator>
      <dc:date>2019-03-11T13:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: C2821 CPU overload</title>
      <link>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102138#M914394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try checking the CPU load during low volume and high volume times. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show proc cpu | e 0.00%  0.00%  0.00%&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think you'll get a definitive answer but it should help point in the right direction. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check this-&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_0t/12_0t4/feature/guide/fw800.html#wp20431" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_0t/12_0t4/feature/guide/fw800.html#wp20431&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CBAC was designed for SMBs, not really Enterprises. I understand that routers work better (and I usually suggest them to my customers), but you might have to figure out new routing techniques and put in a ASA firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 16:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102138#M914394</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-08-18T16:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: C2821 CPU overload</title>
      <link>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102139#M914395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Downgrade the router from an Advanced Sec license to lower and get an ASA &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are pushing the router to its limits it seems. Have you looked at the optimization for CBAC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_2t/12_2t8/feature/guide/ftfirewl.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_2t/12_2t8/feature/guide/ftfirewl.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 18:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102139#M914395</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-18T18:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: C2821 CPU overload</title>
      <link>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102140#M914397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I find quite a lot of %FW log msgs&lt;/P&gt;&lt;P&gt;%FW-6-DROP_TCP_PKT: Dropping tcp pkt xxx =&amp;gt; yyy due to  Invalid Seq# -- ip ident 37313 tcpflags 0x8010 seq.no 2048715884 ack 3899465202&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it an overload symptom ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joined some stat counts in attachment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Aug 2008 14:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102140#M914397</guid>
      <dc:creator>falain</dc:creator>
      <dc:date>2008-08-19T14:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: C2821 CPU overload</title>
      <link>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102141#M914399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for reply, but for now due to budget restrictions, I must face the problem without investments.&lt;/P&gt;&lt;P&gt;CPU is mainly due to outbound http traffic.&lt;/P&gt;&lt;P&gt;1) I moved Http PBR from 2821 to inside C3750E vlan switch.&lt;/P&gt;&lt;P&gt;I hope I will gain 10-20% of CPU.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Http outbound trafic goes to a squid proxy machine.&lt;/P&gt;&lt;P&gt;If I connect Squid's second Eth Int to another Internet IosFW router (using a free public IP address), may be I can reduce CPU overload of 2821.&lt;/P&gt;&lt;P&gt;I guess Http inspect CBAC is the most CPU consumer.&lt;/P&gt;&lt;P&gt;do you know if there is a better IOSFW release which runs CBAC in hardware as ASAs Asic does ?&lt;/P&gt;&lt;P&gt;For now, I run IosFW 12.4.16 standard train.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2008 14:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/c2821-cpu-overload/m-p/1102141#M914399</guid>
      <dc:creator>falain</dc:creator>
      <dc:date>2008-08-26T14:29:30Z</dc:date>
    </item>
  </channel>
</rss>

