cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1150
Views
0
Helpful
5
Replies

mem issue in asa

secureIT
Level 4
Level 4

Hi Netpro Team,

Could you pls check the mem utiliz issue in ASA firewall, attached the logs here....

show local host did not show any high count on /unlimited...so its not an issue from lan attack.

5 Replies 5

varrao
Level 10
Level 10

HI Rajesh,

A few things here:

1.  Has this been your baseline for memory utilization, I mean has it always been this high.

2.  Or have you noticed this memory has been creeping to a higher side recently.

3.  To know your baseline for memory utilization, you can reload the firewall, so after reload theer woudl virtually be no connection on the firewall, and then you can check the output for "show mem", if it still stays above 90%, it could very well just be not enough memory left on the ASA itself and you might just need to upgrade from 256MB.

4.  But if you see that the memory goes down to lets say 60-70% and then creeps up again to 96%, it defintely is a memory leak issue and this needs to be investigated in detail.

5.  In that case, the best option would be to open a TAC case for it to be investigated.

Hope this helps,

Varun

Thanks,
Varun Rao

Hi Varun,

Thanks for the update.... Pls find the below comments..

1.  Has this been your baseline for memory utilization, I mean has it always been this high ---> it is high always

2.  Or have you noticed this memory has been creeping to a higher side recently --> NO

3.  To know your baseline for memory utilization, you can reload the firewall, so after reload theer woudl virtually be no connection on the firewall, and then you can check the output for "show mem", if it still stays above 90%, it could very well just be not enough memory left on the ASA itself and you might just need to upgrade from 256MB -->

-----after the reboot also, the utilization was above 90%

4.  But if you see that the memory goes down to lets say 60-70% and then creeps up again to 96%, it defintely is a memory leak issue and this needs to be investigated in detail.--- No.

---could you pls check if it could be due to software code issue or how is it ??

I am not sure if this could be a software code issue, because the memory utilization always stays high, so this means the memory is being completely used up by the processes runnling on the firewall, and 256MB memory looks not sufficient for the firewall. Even for an upgrade to the next version 8.2.x you would need to upgrade the memory to atleast 1GB, so the best option would be to open a TAC case to get it investigated for a memory issue or software issue.

Thanks,

-Varun

Thanks,
Varun Rao

Hi Varun,

Could you tell me if the below process taking run time value is okay / normal.

show processes -->

Mrd8180744d453d09c09b8a5fc64961049d451d228123332/131072 Dispatch Unit


show process memory -->

AllocsAllocatedFreesFreedProcess
3405941105282379252827376137206Unicorn Admin Thread
8331206160057077688685661627851162IKE Daemon
478213621985000508478180211983589322snmp
675982524877477041735174866536696tacplus_snd
166881594919237933185952277239096389Dispatch Unit

Hi All,

I have investigated on this problem and found that this code is affected with the BUG CSCtg41163.

Symptom:
ASA 5510/w 256 RAM reflect high memory usage in version 8.0.x onwards

Conditions:
High memory usage is seen on ASA platforms with 256 MB RAM, this is only seen
when ASA upgraded to 8.0.x.

Workaround:
Roll back to 7.2 or upgrade to 8.2

Hope this will be useful for others too...

Review Cisco Networking for a $25 gift card