10-12-2023 09:02 AM - edited 11-15-2023 06:59 AM
We are seeing a high CPU usage on our network firewall. Does anyone know what the DataPath process is for?
10-12-2023 09:46 AM
M.
10-12-2023 09:54 AM
what kind of traffic this FW handling?
10-12-2023 10:05 AM
It sits at the perimeter of the network so all traffic traverses through it.
10-13-2023 01:12 AM
what kind of traffic this FW handling? - i mean bandwidth wise, ? post interface output how much utilization.
10-13-2023 05:19 AM - edited 11-15-2023 07:23 AM
oh ok sorry for misunderstanding, this was this morning with low traffic and cpu at 50%:
10-13-2023 02:10 AM
Processes CPU usage is not normal, because it is displayed incorrectly in this version due to CSCvt15348. Actually, it is very high in datapath. This can be caused by high pps rate or high drop rate, so you need to collect "clear traffic" / "show traffic" (once, but wait 1 minute after clearing) and "clear asp drop" / "show clock" + "show asp drop" (thrice) (to see how drops increase over time).
You're running out of 1550B and 80B blocks. The former can be attributed to high CPU. The latter is a bug. Do you encrypt failover link with IPsec? Provide "show run failover".
Conn rate, ACL size, number of xlates is small for this platform.
10-13-2023 02:16 AM
Datapath sometimes is big problem.
Usually Datapath is for VPN (s2s or anyconnect).
If you can open TAC with cisco it better and fast way to know why these processes utilize your FW CPU.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide