cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
548
Views
0
Helpful
2
Replies

High CPU usage on PIX 6.2.2

aun.raza
Community Member

Our PIX has extremely high CPU usage, mostly 99%, with lots of interface overruns. Is there a way to track what is causing such high CPU usage. We have a VPN tunnel running between the sites as well. For that very reason, it keeps locking up every now and then.

Any ideas why this would be happening?

2 Replies 2

mpalardy
Level 6
Level 6

Please see this link:

http://www.cisco.com/warp/customer/110/pixperformance.html#showinterface

What's your interface MTU?

Any other suspect error on pix interfaces?

williamhunt
Community Member

Virus(es) on an inside or dmz host can peg the cpu of the pix. You can try putting an acl on the inside (and/or dmz) interface, and deny some of the commonly attacked ports.

http://www.cisco.com/warp/public/707/advisory.html

http://www.cisco.com/warp/public/707/cisco-sn-20030820-nachi.shtml#pix

http://www.cisco.com/warp/public/707/cisco-sn-20030814-blaster.shtml#pix

If valid traffic is not passing through the pix, you can unplug the inside interface cable; see if that drops the cpu. Patch all inside hosts, and use up-to-date anti-virus.

Note that 6.2.3 is General Deployment code now.

Review Cisco Networking for a $25 gift card