Yes I have seen something very similar to this on FP8100 NGIPS devices.
It's basically due to a high-rate of connections being processed by the device (commonly seen with high rates of DNS traffic for example). Cisco TAC have said to me that there is nothing to be concerned with here however I would recommend raising a TAC case just to verify with them.
Just out of interest, is your connection logging set to Beginning and/or End in the Access Control Policy?
Hope this is OK.
Cheers Phil
Learn, share, save
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.