I recently migrated my ASA5505 (used for Remote Access VPN) to an official DMZ zone. The device currently has one interface, the DMZ interface, which is attached to our DMZ switch then, in turn, our DMZ interface on our firewall. The setup appeared to be running fine, until I noticed the CPU pegged with 95% being allocated to the "Dispatch Unit" process. After doing some additional digging, I'm showing a large number (several thousand/sec) ICMP echo's coming from one of my internal addresses being sent to an address that's used for IPSec remote access. However, when looking at the internal server, I see no such ICMP's being generated. For whatever reason, it appears the ASA is generating these packets itself. My reasoning being, when I reload the ASA, the bandwidth usage on my firewall (for the DMZ interface) drops dramatically and I no longer see said ICMP packets. I hope this makes sense, I have no idea what to think.
Thank you for your time!