09-01-2024 07:41 PM
Hello Cisco Team,
I would like to inquire about the FMC software that I have integrated with the ASA firewall. There is a critical alert indicating "Frequent drain of Connection Events" related to disk usage. However, when checking the health dashboard, the disk status does not appear to be full or in failure. You can see this in the image below.
Could your team please provide an explanation regarding this issue?
Thank you.Health status
alert
09-02-2024 12:13 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd26466
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz86604
M.
09-02-2024 03:54 PM
We had this issue previously. It was fixed for us after upgrading to version 7.2.5.
09-02-2024 07:07 PM
I am already on version 7.2.5.2. Is there a way to remove or clear those alarms?
09-03-2024 12:04 AM
Are you by chance logging ACP rules at both beginning and end ?
09-03-2024 12:28 AM
Your health status screenshot appears to be from your device running FTD. Can you share the health screenshot for FMC including events/second? That is the usual culprit for the error message (which basically says the FMC's ability to write incoming events to the database on disk is overwhelmed). The bug cited by @marce1000 are also a possibility. Although they should be fixed in your FMC version, bugs from earlier releases have been known to persist across an upgrade from an affected version.
09-03-2024 08:13 PM
this the health screenshot for FMC.
09-03-2024 09:10 PM - edited 09-03-2024 09:11 PM
The FMC health shows less than 4k events/second (connections, intrusion etc. combined) yet the input rate is constant up around 25 Mbps - that is quite unusually high. Something is send a LOT of data to the FMC for processing but it doesn't look like connection events. Do you possibly have firewall debugging enabled and set via platform policy to send events to FMC?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide