06-16-2023 05:15 AM
Hi,
I've noticed when a particular on-prem host downloads a large dataset from AWS S3 using SSL/TLS on tcp 443, my FTD 6.6.5.2 has its LINA CPU spike by 20%-25%. The flow is 800Mbps for several hours. I identifed the traffic and fastpathed it using pre-filter but that made no difference. If fastpath didn't help then IAB for snort won't either. The LINA cpu is a total mystery -its always high even under modest load, but this 20% spike uses up any apparent spare capacity. I didn't experience any interruption to services but running at 97 to 99% for hours can't be good.
One thought I had is to allow the on-prem host access to internet udp 443 as well as tcp 443 - could that help?
Has anyone experienced anything like this and been able to mitigate?
I am planning to upgrade to the recommended 7.0.5 - maybe that will help.
Solved! Go to Solution.
06-20-2023 02:04 AM
06-23-2023 08:41 AM
It all depends on the hardware platform in use, but 800Mbps flows like this can potentially cause performance issues on any ASA or Firepower platform. Even on high-end multicore appliances each flow is owned and handled by a single CPU core, so single CPU core performance can become a bottleneck, "no buffer" or "overrun" counters will increment as well as dispatch-queue-limit "show asp drop" drops on multicore platforms.
Upgrade to 7.0.5 definitely won't help in this scenario, because this is an architectural limitation of the software.
06-20-2023 02:04 AM
06-23-2023 08:41 AM
It all depends on the hardware platform in use, but 800Mbps flows like this can potentially cause performance issues on any ASA or Firepower platform. Even on high-end multicore appliances each flow is owned and handled by a single CPU core, so single CPU core performance can become a bottleneck, "no buffer" or "overrun" counters will increment as well as dispatch-queue-limit "show asp drop" drops on multicore platforms.
Upgrade to 7.0.5 definitely won't help in this scenario, because this is an architectural limitation of the software.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide