<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic High CPU on ASA5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714152#M978435</link>
    <description>&lt;P&gt;We migrated our old Borderware firewall to Cisco asa5520 and noticed the CPU on it always over 30% and sometime over 60%/70%. I was wondering if there is anything I can do to improve performance and resolve this issue. &lt;/P&gt;&lt;P&gt;The interfaces looks okay and we have about 15MB internet pipe so it's not heavey usage configuaration. It also has 51 3des Site-to-Site VPN tunnels. I am thinking about enabling CSC module and start scanning http/email but I am not sure if I should go forward that until I resolve cpu issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.2(2)&lt;/P&gt;&lt;P&gt;Device Manager Version 5.2(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Wed 22-Nov-06 14:16 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa722-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;catoactive up 5 days 14 hours&lt;/P&gt;&lt;P&gt;failover cluster up 7 days 3 hours&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   ASA5520-K8, 512 MB RAM, CPU Pentium 4 Celeron 2000 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 256MB&lt;/P&gt;&lt;P&gt;BIOS Flash AT49LW080 @ 0xffe00000, 1024KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0&lt;/P&gt;&lt;P&gt;                             Boot microcode   : ☻CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: ♥CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : ☺CNlite-MC-IPSECm-MAIN-2.04&lt;/P&gt;&lt;P&gt; 0: Ext: GigabitEthernet0/0  : address is 0019.0665.6964, irq 9&lt;/P&gt;&lt;P&gt; 1: Ext: GigabitEthernet0/1  : address is 0019.0665.6965, irq 9&lt;/P&gt;&lt;P&gt; 2: Ext: GigabitEthernet0/2  : address is 0019.0665.6966, irq 9&lt;/P&gt;&lt;P&gt; 3: Ext: GigabitEthernet0/3  : address is 0019.0665.6967, irq 9&lt;/P&gt;&lt;P&gt; 4: Ext: Management0/0       : address is 0019.0665.6968, irq 11&lt;/P&gt;&lt;P&gt; 5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11&lt;/P&gt;&lt;P&gt; 6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : Unlimited&lt;/P&gt;&lt;P&gt;Maximum VLANs               : 150&lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited&lt;/P&gt;&lt;P&gt;Failover                    : Active/Active&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled&lt;/P&gt;&lt;P&gt;Security Contexts           : 2&lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled&lt;/P&gt;&lt;P&gt;VPN Peers                   : 750&lt;/P&gt;&lt;P&gt;WebVPN Peers                : 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has an ASA 5520 VPN Plus license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: &lt;/P&gt;&lt;P&gt;Running Activation Key: 0xb9012b61 Configuration register is 0x1&lt;/P&gt;&lt;P&gt;Configuration last modified by sysadmin at 17:18:14.257 PDT Wed Jun 13 2007&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:30:46 GMT</pubDate>
    <dc:creator>ciscoforumuser</dc:creator>
    <dc:date>2019-03-11T10:30:46Z</dc:date>
    <item>
      <title>High CPU on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714152#M978435</link>
      <description>&lt;P&gt;We migrated our old Borderware firewall to Cisco asa5520 and noticed the CPU on it always over 30% and sometime over 60%/70%. I was wondering if there is anything I can do to improve performance and resolve this issue. &lt;/P&gt;&lt;P&gt;The interfaces looks okay and we have about 15MB internet pipe so it's not heavey usage configuaration. It also has 51 3des Site-to-Site VPN tunnels. I am thinking about enabling CSC module and start scanning http/email but I am not sure if I should go forward that until I resolve cpu issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.2(2)&lt;/P&gt;&lt;P&gt;Device Manager Version 5.2(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Wed 22-Nov-06 14:16 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa722-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;catoactive up 5 days 14 hours&lt;/P&gt;&lt;P&gt;failover cluster up 7 days 3 hours&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   ASA5520-K8, 512 MB RAM, CPU Pentium 4 Celeron 2000 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 256MB&lt;/P&gt;&lt;P&gt;BIOS Flash AT49LW080 @ 0xffe00000, 1024KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0&lt;/P&gt;&lt;P&gt;                             Boot microcode   : ☻CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: ♥CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : ☺CNlite-MC-IPSECm-MAIN-2.04&lt;/P&gt;&lt;P&gt; 0: Ext: GigabitEthernet0/0  : address is 0019.0665.6964, irq 9&lt;/P&gt;&lt;P&gt; 1: Ext: GigabitEthernet0/1  : address is 0019.0665.6965, irq 9&lt;/P&gt;&lt;P&gt; 2: Ext: GigabitEthernet0/2  : address is 0019.0665.6966, irq 9&lt;/P&gt;&lt;P&gt; 3: Ext: GigabitEthernet0/3  : address is 0019.0665.6967, irq 9&lt;/P&gt;&lt;P&gt; 4: Ext: Management0/0       : address is 0019.0665.6968, irq 11&lt;/P&gt;&lt;P&gt; 5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11&lt;/P&gt;&lt;P&gt; 6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : Unlimited&lt;/P&gt;&lt;P&gt;Maximum VLANs               : 150&lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited&lt;/P&gt;&lt;P&gt;Failover                    : Active/Active&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled&lt;/P&gt;&lt;P&gt;Security Contexts           : 2&lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled&lt;/P&gt;&lt;P&gt;VPN Peers                   : 750&lt;/P&gt;&lt;P&gt;WebVPN Peers                : 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has an ASA 5520 VPN Plus license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Serial Number: &lt;/P&gt;&lt;P&gt;Running Activation Key: 0xb9012b61 Configuration register is 0x1&lt;/P&gt;&lt;P&gt;Configuration last modified by sysadmin at 17:18:14.257 PDT Wed Jun 13 2007&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714152#M978435</guid>
      <dc:creator>ciscoforumuser</dc:creator>
      <dc:date>2019-03-11T10:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714153#M978437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have large ACL's applied to the interfaces?  If so it might be worth checking which lines are getting the most hits and re-writing the ACLs so the most 'active' items are listed first, etc.&lt;/P&gt;&lt;P&gt;Just a thought,&lt;/P&gt;&lt;P&gt;Carl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2007 19:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714153#M978437</guid>
      <dc:creator>1cmerchant</dc:creator>
      <dc:date>2007-06-15T19:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714154#M978439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Cisco TAC is saying that it's normal for ASA cpu running around 30%. Since last night the CPU usage is about 1-5% and nothing has changhed since yesterday so It does not make sense. This has to be bug or something. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2007 16:00:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714154#M978439</guid>
      <dc:creator>ciscoforumuser</dc:creator>
      <dc:date>2007-06-19T16:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714155#M978441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you having a high connection rate? (sh conn count) You said 51 site to site tunnels. If you do a "sh cry isa sa" What state are the crypto tunnels in? qm_idle? mm key exchange? Post your connection count when this happens again and an example of some of the connections(block out IPs of course)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2007 16:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714155#M978441</guid>
      <dc:creator>JBDanford2002</dc:creator>
      <dc:date>2007-06-19T16:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714156#M978442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is SH cont with cpu about 30%&lt;/P&gt;&lt;P&gt;sh conn count&lt;/P&gt;&lt;P&gt;1469 in use, 2974 most used&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Type    : L2L             Role    : initiator&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is sh cry results, most of them in MM_Active State. Most of our tunnels rarely used (less than few pages printout)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sh cry isa sa &lt;/P&gt;&lt;P&gt;Active SA: 48&lt;/P&gt;&lt;P&gt;Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey&lt;/P&gt;&lt;P&gt;Total IKE SA: 48&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1   IKE Peer: x.x.x.x    Type    : L2L             Role    : responder&lt;/P&gt;&lt;P&gt;    Rekey   : no              State   : MM_ACTIVE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will keep checking conn counts when CPU peaks again..thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2007 17:08:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/high-cpu-on-asa5520/m-p/714156#M978442</guid>
      <dc:creator>ciscoforumuser</dc:creator>
      <dc:date>2007-06-19T17:08:15Z</dc:date>
    </item>
  </channel>
</rss>

