02-20-2013 11:51 PM - edited 03-11-2019 06:03 PM
- ASA5545 : Software Version 8.6(1)2
Connection table (cfwConnectionStatValue) gradually increases and never goes down. Upon 750000
connections, user activity is hampered and the box claims that it can not support more connections.
Is there a remedy ?
M.
Solved! Go to Solution.
02-21-2013 01:13 AM
Hi,
I think on the ASDM side you can go to the "Home" window and a little bit below you will see the "Tabs" called "Device Dashboard" which is selected by default and "Firewall Dashboard" that you should go to.
It has other statistics and on the lower right hand corner there is an option to go through different Top statistics.
I have a vague memory that this might cause performance issues in worst case. But it should probably be the easiest way to get information through the ASDM
Otherwise you just have to monitor the "show conn" , "show conn count" , "show conn long" , "show local-host" and other similiar command outputs to gather information.
- Jouni
02-20-2013 11:55 PM
Hi,
Have you made changes to the default "timeout" values shown with the command "show run timeout" ?
Is there some host on the network that is generating so much connections that its eating up the ASA resources.
I have witnessed a couple of times a single host generating so much connections/traffic that it has exhausted the set connection limit of the ASA (Though in this case a bit lower end model of ASA)
- Jouni
02-21-2013 12:15 AM
>Is there some host on the network that is generating so much connections that its eating up the ASA resources ?
Tx, is there a way in ASA, command line, or device mgr, which can show me the 'top-connecting' hosts
(so to speak).
Marc.
02-21-2013 01:13 AM
Hi,
I think on the ASDM side you can go to the "Home" window and a little bit below you will see the "Tabs" called "Device Dashboard" which is selected by default and "Firewall Dashboard" that you should go to.
It has other statistics and on the lower right hand corner there is an option to go through different Top statistics.
I have a vague memory that this might cause performance issues in worst case. But it should probably be the easiest way to get information through the ASDM
Otherwise you just have to monitor the "show conn" , "show conn count" , "show conn long" , "show local-host" and other similiar command outputs to gather information.
- Jouni
02-21-2013 11:55 PM
Tx, it turns out, that during initial setup of the firewall, some rules had the 'service policy' setup set to
infinite TCP timeouts for app-debugging. We are now reviewing the service policy rules and making
corrections were needed.
Marc.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide