cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
244
Views
0
Helpful
1
Replies

IDSM Blocking Cause Cat6509 High CPU Loading

alomar818
Level 1
Level 1

Dear All:

Does anybody has the same question?When I enable the IDSM2 Signature to blocking,the IDSM2 telnet to blocking device Catalyst 6509,and config the ACL to deny ip hosts.But this action cause the Catalyst 6509 CPU loading up to 50%~70%,and cause the user's campus network become slow.Have any solution can solve this problem?

Thanks everybody...

1 Reply 1

marcabal
Cisco Employee
Cisco Employee

This is generally an issue more with the switch than the IDSM-2.

The switch has a maximum supported number of ACL enties. You need to ensure that you have not configured the IDSM-2 to create more than this number of entries.

NOTE: The IDSM-2 creates 2 ACLs for each vlan being managed. So to calculate the number of ACL entries you need to determine the number of hosts being denied then multiply by the number of vlans being managed and then multiple by 2 in order to get the number of acl entries.

If the IDSM-2 is creating less than the maximum number of entries then this would be more of a switch question than an IDSM-2 question. You will need to contact the TAC to request their assistance in trying to determine what is going on with the switch.