cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
719
Views
0
Helpful
1
Replies

FWSM with contexts - Broadcast storm impact CPU

feliperodero
Level 1
Level 1

Hi,

we have a FWSM (4.1(5)) configured with several contexts.

Last day we had a broadcast storm in one VLAN connected to one FWSM context and all contexts were impacted with loss of service.

We could check that CPU in impacted context went to 50 - 60 % but in fact service allocated in other contexts were impacted.

We have Resource Class implemented, but there is nothing about CPU usage (only connections, xlates, .... ).

Any idea about how to protect contexts against a broadcast storm or high CPU usage in one context ?

Thanks a lot

Felipe

1 Reply 1

mirober2
Cisco Employee
Cisco Employee

Hi Felipe,

Unfortunately, the FWSM's CPU is not virtualized across contexts like the conn tables, xlate tables, etc are. High CPU caused by traffic in one context will indeed affect traffic on other contexts on the same physical firewall, which is a limitation of the architecture.

-Mike

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card