cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
362
Views
0
Helpful
2
Replies

High CPU usage on PIX 6.2.2

aun.raza
Level 1
Level 1

Our PIX has extremely high CPU usage, mostly 99%, with lots of interface overruns. Is there a way to track what is causing such high CPU usage. We have a VPN tunnel running between the sites as well. For that very reason, it keeps locking up every now and then.

Any ideas why this would be happening?

2 Replies 2

mpalardy
Level 3
Level 3

Please see this link:

http://www.cisco.com/warp/customer/110/pixperformance.html#showinterface

What's your interface MTU?

Any other suspect error on pix interfaces?

williamhunt
Level 1
Level 1

Virus(es) on an inside or dmz host can peg the cpu of the pix. You can try putting an acl on the inside (and/or dmz) interface, and deny some of the commonly attacked ports.

http://www.cisco.com/warp/public/707/advisory.html

http://www.cisco.com/warp/public/707/cisco-sn-20030820-nachi.shtml#pix

http://www.cisco.com/warp/public/707/cisco-sn-20030814-blaster.shtml#pix

If valid traffic is not passing through the pix, you can unplug the inside interface cable; see if that drops the cpu. Patch all inside hosts, and use up-to-date anti-virus.

Note that 6.2.3 is General Deployment code now.

Review Cisco Networking for a $25 gift card