Problem Statement: SR520 system is crashing and/or unresponsive when IPS is configured
Root Cause: The system is running out of memory due to enabling IPS and ZBFW feature set above other typical configuration.
Possible solutions:
- Move to 151.1.T image which supports a new IPS feature to limit the amount of memory threshold. This is critical for low end platforms which have limited DRAM.
- Reduce the IO memory to 5% from 10% to free up some DRAM for IPS.
- Configure, download, compile and enable signatures and verify that it is working in his setup.
- Fine tune IPS by selecting specific signature categories based on available memory and need.
- Identify new IPS signature location for 5.x signatures. The new location is only for CCA. Customers can still download the latest package files using CCO.
Other useful links:
IPS DOWNLOAD instructions:
http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6634/prod_white_paper0900aecd805c4ea8.html
FAQ:
https://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6634/prod_qas0900aecd806fc530.html