cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3138
Views
3
Helpful
30
Replies

ASA 5525 - High Memory Utilization

uadmin
Level 1
Level 1

Hello,

Our ASA 5525 (IOS 9.14.4.24) is experiencing high memory utilization.      

This is what I see so far:

fw1# show memory
Free memory: 815972661 bytes (18%)
Used memory: 3575802776 bytes (82%)
------------- ------------------
Total memory: 4391775437 bytes (100%)

 

I checked the log level and found this:

internet-fw1# show logging setting
Syslog logging: enabled
Facility: 20
Timestamp logging: enabled
Timezone: enabled
Hide Username logging: enabled
Standby logging: disabled
Debug-trace logging: disabled
Console logging: disabled
Monitor logging: disabled
Buffer logging: level debugging, 133637032 messages logged
Trap logging: level informational, facility 20, 382838012 messages logged
Logging to net1-c6509 192.168.17.190, UDP TX:163286
Logging to net1-c6509 192.168.17.86, UDP TX:163286
Global TCP syslog stats::
NOT_PUTABLE: 0, ALL_CHANNEL_DOWN: 0
CHANNEL_FLAP_CNT: 0, SYSLOG_PKT_LOSS: 0
PARTIAL_REWRITE_CNT: 0
Permit-hostdown logging: enabled
History logging: disabled
Device ID: disabled
Mail logging: disabled
ASDM logging: level informational, 127714278 messages logged

 

* I changed the buffer logging to 'alert' level but free memory only improved by 1%.

fw1# show memory detail

Heap Memory:
Free Memory:
Heapcache Pool: 3194256 bytes ( 0% )
Global Shared Pool: 57664448 bytes ( 1% )
Message Layer Pool: 3985264 bytes ( 0% )
System: 482221261 bytes ( 11% )
Used Memory:
Heapcache Pool: 684671600 bytes ( 16% )
Global Shared Pool: 2510613568 bytes ( 57% )
Reserved (Size of DMA Pool): 230686720 bytes ( 5% )
Reserved for messaging: 209040 bytes ( 0% )
MMAP usage: 21370056 bytes ( 0% )
System Overhead: 397159224 bytes ( 9% )
------------------------------------- ----------------
Total Memory: 4391775437 bytes ( 100% )



uadmin_0-1746030326183.png

 

Any idea how to lower the memory utilization?  

I wasn't able to find any bugs related to my IOS version.   Furthermore, this ASA model can not go above 9.14.4.24




 

30 Replies 30

How do I make it NOT keep it locally???? I want to free up the buffer.

Log buffer have level 1 

External server have level above 1 

When you move message then the message will send to server abd not full the buffer.

MHM

"When you move message then the message will send to server abd not full the buffer."


I understand that Sir, but what command do I use to tell the box to send the logs to the syslog only, and stop sending it to the buffer? What is the command please?

uadmin
Level 1
Level 1

Nvm, I think I found it.  

no logging buffered

This will sure not make buffer saving any message.

As I mention before it depend on your requirement' you can move message or not save any messages in buffer.

MHM

uadmin
Level 1
Level 1

I disabled the internal buffer for logging but memory still high, even after clearing the buffer.

 

 

uadmin_0-1746219436591.png

 

Do I need to disable logging for the 'ASDM' as well to free up the memory?

 

 



Yes

MHM

uadmin
Level 1
Level 1

uadmin_0-1746219876606.png

This is what I have right now, how long will it take the memory to clear?

Will I need to reboot the box at all?

no need reboot, monitor ASA for couple of hours 

MHM

Ok, I just got home.  Looking at it, a bit concerned, the memory keeps getting depleted. 

 

uadmin_0-1746230492561.pnguadmin_1-1746230531650.png

Anything else I can do? Did I miss anything?

johnlloyd_13
Level 9
Level 9

hi,

temporarily remove logging and clear log buffer.

no logging enable

clear logging buffer

 

Firewall won't let me SSH into it anymore, closes my SSH connection. 

Going to try this from the GUI.

uadmin
Level 1
Level 1

Looks like I can't connect to it via ASDM or SSH at this point.     Going to reboot it and/or failover to the secondary.

 

  - @uadmin  It got out of sufficient resources eventually; you may try the CLI Analyzer again , to check if that was related too and or for demo purposes and discover its functionalities.

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

The Cisco CLI Analyzer (v3.7.2) can't seem to connect to the firewall, regardless of what I try.    All I see is an empty screen with a blinking cursor.

uadmin_0-1746444730562.png

 

We had to failover to the secondary firewall yesterday.  Now that the primary isn't active, I am looking at it without it processing traffic or creating logs and it is still filling up the memory by about 8% a day.