cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2115
Views
0
Helpful
14
Replies

High CPU due to packet capture

Hi,

IF we do not remove packet capture on ASA does it cause CPU to spike?

Regards,

Krishna

14 Replies 14

Hi,

Still awaiting ur reply

whether a single src to single dst pcap or network ?

ideally not recommended to keep the pcap enabled, but still less impact on asa.

instead of you deciding pcap as a source of high cpu, it would be better to check whether its a cosmetic bug or genuine bug.

regards

Rajesh

Hi,

There were 4 packet caps running on the device all were SRC to DEST.

How much CPU does each packet cap can take.

Regards,

Krishna

Pls ask if you have some other queries. Only development team can answer to ur qsn.

Cpu was alright when captures were removed so just wanted to make sure it was due to that

Vibhor Amrodia
Cisco Employee
Cisco Employee

Did we have circular buffer captures enabled ? Which asa device are you seeing this issue on ?

No. Circualr buffer was nt enabled, my question is once the buffer is full, will that lead to high CPU or not. The ASA is 5540

Hi Krishna,

We have seen this problem before on some TAC cases and we do have a Bug Defect for the same issue.

Although this Bug Defect is not resolved as we were not able to recreate the issue.

Hi,

Thanks very much replying, so ideally it should be dropping the packets once the buffer is full.

Regards,

Krishna

Here is the packet cap that was on the firewall.

capture cap1 type        raw-data interface PATSv2 [Buffer Full - 523510 bytes]
match ip any        host 87.236.65.84
capture cap2 type raw-data interface PATSv2 [Buffer        Full - 523510 bytes]
match ip host 87.236.65.84 any
capture CAP1        type raw-data interface market_server_dmz [Capturing - 1476 bytes]
match        ip host 172.16.96.12 host 172.21.62.104
capture CAP2 type raw-data        interface inside [Capturing - 1170 bytes]
match ip host 172.16.96.12        host 172.21.62.104
So is it confirmed that CPU got spiked by bug defect. ?
Regards,
Krishna

Still awaiting ur reply

Hi Krishna,

Can you post the CPU status increase with the captures apllied on the ASA so that we can verify the increase.

If the capture Buffer is full , the captures would not have any impact on the ASA device and the respective interface and no further traffic would be captured.

The Bug Defect is not resolved and we were not able to recreate the issue in lab.

If you are able to recreate the issue in Lab , i would request you to open a TAC case and we might try to resolve the Bug Defect.

Thanks and Regards,

Vibhor Amrodia

hkaraeen
Cisco Employee
Cisco Employee

could you please provide me with bug id

 

E.g. CSCta43472

 

Review Cisco Networking products for a $25 gift card