Hello Techies,
I'm facing high CPU utilization (96%) issue on Cisco ASA (ASA5545). We have two ASA Firewall running Anyconnect with VPN load-balancing. We noticed high CPU utilization (around 96%) on FW. After further troubleshooting, we noticed that VPN clients are generating packets for broadcast IP (10.199.226.255 & 10.199.227.255) address that causing routing loop on FW and resulting high CPU utilization.
Below the User pool configured on both FW.
ASA1 -- ip local pool vpn-1 10.199.226.1-10.199.226.254 mask 255.255.255.0
ASA2 -- ip local pool vpn-2 10.199.227.1-10.199.226.254 mask 255.255.255.0
Below is the captured from FW.
Why the VPN clients are generating broadcast packets and how to stop them?
Thanks,