03-14-2023 03:22 AM
Hello,
we are having fts 2110 (A-S) managed by FMC version 7.0.1 since long time without issues. Suddenly today morning we are seeing high cou usage in active FTD exceeding 87percent.
Overtime it got settled on 39%, which i feel is still high.
After executing the top command, i see snort is taking-up 21% of the cpu resource.
Now i dont know how to reduce it or to identify the cause and rectify.
appreciate your guidance
03-14-2023 03:30 AM
@shaikh.zaid22 you should upgrade your FTD, the latest cisco recommended version is 7.0.5.
There are a couple of CPU related issues resolved since 7.0.1 https://www.cisco.com/c/en/us/td/docs/security/firepower/70/relnotes/firepower-release-notes-700/bugs.html
03-14-2023 04:56 AM
Thanks Rob.
But the bug list does not match our case, this bug is for the standby ftd CSCvy78209, in my case we have it for primary ftd.
plus am running this version since more than a year without issues. Is there a way to suppress this snort high usage?
03-14-2023 05:05 AM
@shaikh.zaid22 log a call with TAC, who'll probably suggest and upgrade anyway.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide