09-02-2004 08:53 PM - edited 02-20-2020 11:36 PM
Dear Glen,
The PIX is switching over to failover mode due to high CPU utilization. We Changed the xlate timeout value to 3 hrs. PIX switched over to failover mode thrice in the evening within 1hour duration. We opened a TAC case for the issue. CISCO TAC engineer suggested it is a bug (CSCed59572). We Upgraded the IOS to 6.3.3.133. Utilization was under control. After 2 months the problem again cropped up. TAC engineer suggested The Bug ID has been updated instead of 633.133 it was move in to 633.138.
The TAC engineer decided to provide new version 6.3.4. After upgrading also utilization was high. TAC engineer suggested Turbo-acl. It has come down to 60% from 98%. The xlate-timeout. But currently the site is going to handle 1000 new nodes. Currently they have got 3000 users.
Turbo- ACL is difficult since they change access-list on daily basis.
I am attaching the required log file.Please let me know how I should proceed further.
09-04-2004 11:43 AM
Hi,
Could you provide the output of "show xlat count" & "show conn count". Also "show interface", "show cpu usage", "show proc"
Thanks
Nadeem
09-05-2004 08:00 PM
Please find the attachments
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide