09-07-2023 12:04 AM
Hi,
I have two FTD's managed by FMC. at times its cpu hits 100 % . I figured out that when there is heavy traffic passing through two interfaces the snort process chokes one cpu.
there is 230Mbps data throughput between two zones/interfaces on FTD when i noticed this problem. At the moment i have not enabled netflow .so what else can i use to find the source and destination IPs that were involved in above communication so i can tune ips/file policy for that.
Regards
09-07-2023 12:25 AM
what FMC version ? is this VM ?
I have noticed this when the FTD sending too many logs to FMC
09-07-2023 01:05 AM
FMC Software Versio 7.0.4
above is fmc version. Pardon me. the cpu on one of the core of ftd is hitting 100% and staying there as long as the trhough put on interface 221 Mbps. The ftd is 2110 v7.0.1.
I need to figure out what source/dest was involved in that big data copy. so i can tune policy on that.
09-08-2023 06:33 AM
You could enable IAB in monitor mode and see if that identifies the source/destination the next time your snort process hist 100% CPU. IAB will log a connection event with 'Would Bypass' when triggered.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide