cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1374
Views
0
Helpful
2
Replies

ASA-SSC-AIP-5 Analysis Engine Not Responding

Mark^
Level 1
Level 1

Every couple of days I have been noticing that the IPS is in bypass mode and the Analysis Engine Status is often shown as not responding or is still loading something, and naturally, the CPU is pegged at 100%... so I have been reloading the IPS when this happens.

2 Questions:

  1. Any general pointers of what often causes this, or things that I should look for when this is happening?  I know I did not give enough details for specific answers, but I am just looking for general ideas to start with.
  2. More importantly, what syslog messages might show up in the logs when the IPS goes into Bypass mode?  I'd like to setup a notification for these syslog messages so that I can troubleshoot immediately and determine the cause.

IPS Version 6.2(2)E4

Signature Version 559.0

Cisco Adaptive Security Appliance Software Version 8.3(2)13

Thanks.

Mark
2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

I would suggest that you upgrade the AIP-5 software to the latest version: 6.2.3(E4).

Here is the release notes where a number of memory related bugs have been resolved:

http://www.cisco.com/web/software/282549758/38029/IPS-6_2-3-E4_readme.txt

You might also want to check if the AIP-5 module is overloaded with traffic, which can cause that issue.

Mark^
Level 1
Level 1

Thank you.  I did not see that was available.  I have applied the update and will monitor it for a while.  Hopfully that's all it was!

As fr as the syslog messages, I think I got what I needed via the ASA syslog.

Thanks!

Mark
Review Cisco Networking for a $25 gift card