cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
843
Views
0
Helpful
4
Replies

High CPU due to dispatch unit process in cisco ASA 5520

anoop verma
Level 1
Level 1

dispatch unit process using almost 100% CPU; frequency of the incident is 2 hours; FW get hanged and after removing the cable from FW, it get stable; again same after 2 hours;

 

hardware:- asa 5520

 

topology:- 

 

SW 2960----------FW5520_______asr1002

tcp connection sudennely increases to 5K, under normal condition it was less than 100;

 

Kindly share resolution steps;

4 Replies 4

Check if you are under attack.

get the output of show perfmon

yes, as per my observation its a dos attack; few host(like 10.x.y.20) establishing tcp connection with 10.x.y.255 over port number 445; after scan that host 20 virus found; i want to isolate this;

Ok. Attack on 445 isn't good. You should imlpment wannaCry ACLs
immediately.

pls share configuration;

Review Cisco Networking for a $25 gift card