cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
373
Views
0
Helpful
2
Replies

IOS IPS CPU Utilization

nleachman
Level 1
Level 1

Hi,

I'm hoping that I can ask a question here about the IPS function built into the AdvSec versions of IOS?

I have experimented with implementing the default signature set on 3845's (12.4 mainline, 1GB dram) - and it works well; but the CPU utilization jumps from around 10% to ~30% - without any other changes.

Is this much of a jump to be expected? And, is there any "tuning" that can be done to bring it down significantly?

Thanks, Nick

2 Replies 2

Adam Frederick
Level 3
Level 3

Nick;

This is normal and can be tuned (i.e disable sigs for any protocols not in use). I would suggest using the 256MB signature definition file, as that is what I am using and it doesn't add much more overhead than builtin sigs. I have one 2811 in particular feeding 2 T1s w/ MLPPP and taking advantage of the Firewall & IPS features. These 2 features alone only added around 13% extra CPU utilization on this small box.

Adam,

Thank you for the reply.

I really appreciate knowing that the sharp jump is to be expected - I was expecting something less than a 100% increase in CPU; and it's helpful to know that the 256 sig set is close in performance to the built-ins.

Many thanks,

Nick

Review Cisco Networking for a $25 gift card