12-28-2004 09:52 AM - edited 03-09-2019 09:52 AM
hi all , how can i identify the process that cause pix 515's percent of cpu to increse from a normal 5% to 75% slowing down the connection ?
I have tried with sh cpu usage , sh proc but i cannot look at which process for a 5 minute every hour (more or less) block the firewall.
thks in advance
12-28-2004 11:56 PM
Check
"show conn" to see if any particular IP is sending traffic continously.
12-29-2004 01:38 AM
thks for answer , i already looked at this command but if i have understood well it shows the connection being established or already established but also if there isn't traffic that flood into so i could have for example 100 connection established with few traffic into them without give me the real traffic. what do you think about?
bye
12-29-2004 02:31 AM
If your PIX Firewall Version is 6.3(3) then perfmon command lets you monitor the PIX Firewall units performance and "show perfmon"which gives you traffic idea like this
PERFMON STATS: Current Average
Xlates 0/s 0/s
Connections 79/s 0/s
TCP Conns 67/s 1/s
UDP Conns 11/s 2/s
URL Access 47/s 1/s
URL Server Req 0/s 0/s
TCP Fixup 1846/s 2/s
TCPIntercept 0/s 0/s
HTTP Fixup 1690/s 0/s
FTP Fixup 0/s 0/s
AAA Authen 0/s 0/s
AAA Author 0/s 0/s
AAA Account 0/s 0/s
and then you can use the "capture" command to capure the specific traffic .
HTH,
Sachin Jain
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide