cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
460
Views
0
Helpful
1
Replies

High CPU utilization on 6500

sasa.rasovic
Level 1
Level 1

Hi,

Well, I have this strange problem with 6500 and 4215. Everything works just fine, sensor is blocking and no real problem with that.

But, I get high cpu usage on my 6500 device whenever IDS is accessing it for ACL configuration.

I tried to sniff on this and I get this strange output from 6500 device whenever ssh session is established: 6500 is responsing one letter at a time (I mean one letter per packet), so it takes a lot of packets in order to this session to get accomplished.

Here is a log from 4215 :

"evError: eventId=1114377191440638275 severity=error

originator:

hostId: xxx

appName: nac

appInstanceId: 1162

time: 2005/08/17 14:40:14 2005/08/17 16:40:14 Summer

errorMessage: name=errSystemError ERROR: Syntax error from invalid input at device [Cisco] IP [x.x.x.x] state [Active]Text from device:

^

% Invalid input detected at '^' marker.

sw-01(config-if)# "

Anyone seen this before.

Just to mention, regular telnet/ssh sessions are not cpu intensive.

Thanks,

Sasa

1 Reply 1

umedryk
Level 5
Level 5

This could be due to very large ACLs and ACEs that you might be having. I wonder if there is a turbo acl ( as in pix) is there in IDS. If so, this will reduce the consumption of resources to a large extent.

Review Cisco Networking for a $25 gift card