cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
501
Views
0
Helpful
1
Replies

high cpu firewall module

alfredoelias
Level 1
Level 1

I have high cpu on my firewall module which has the next IOS version FWSM Firewall Version 3.1 (5)
Device Manager Version 5.0 (2) the problem is that if I put an access-list new CPU rises to 75% when the average is 15%. After applying the access-list and wait a while returns to normal CPU. I thank you very much for your help.

Thanks,

1 Reply 1

mirober2
Cisco Employee
Cisco Employee

Hello,

This is normal behavior for the FWSM platform. When you add or make a change to an access-list, the CPU has to re-compile the entire ACL and then push it down into the network processors who actually evaluate the incoming traffic.

The CPU will rise while this compilation takes place, but the process will constantly yield to other processes so that the compilation process does not affect your traffic.

Hope that helps.

-Mike

Review Cisco Networking for a $25 gift card