cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
412
Views
0
Helpful
2
Replies

pix 525 high cpu utilization

hbaski
Level 1
Level 1

Dear Glen,

The PIX is switching over to failover mode due to high CPU utilization. We Changed the xlate timeout value to 3 hrs. PIX switched over to failover mode thrice in the evening within 1hour duration. We opened a TAC case for the issue. CISCO TAC engineer suggested it is a bug (CSCed59572). We Upgraded the IOS to 6.3.3.133. Utilization was under control. After 2 months the problem again cropped up. TAC engineer suggested The Bug ID has been updated instead of 633.133 it was move in to 633.138.

The TAC engineer decided to provide new version 6.3.4. After upgrading also utilization was high. TAC engineer suggested Turbo-acl. It has come down to 60% from 98%. The xlate-timeout. But currently the site is going to handle 1000 new nodes. Currently they have got 3000 users.

Turbo- ACL is difficult since they change access-list on daily basis.

I am attaching the required log file.Please let me know how I should proceed further.

2 Replies 2

nkhawaja
Cisco Employee
Cisco Employee

Hi,

Could you provide the output of "show xlat count" & "show conn count". Also "show interface", "show cpu usage", "show proc"

Thanks

Nadeem

Please find the attachments

 

 

 

Review Cisco Networking for a $25 gift card