11-05-2004 05:50 PM
What are the possible reasons for CPU in PIX 520 to be high ?
What is the max traffic that can pass on outside interface ?
what is the command to check for the max number of concurrent connections ?
11-05-2004 11:37 PM
Hello shankar,
most of the times, it is some high traffic or worms, that increase the CPU in PIX. you can check this, if you have a syslog server on the inside and see the outputs in that. As a practice, block icmp, snmp, & all other vulnarable applications on the PIX.
the max traffic that the outside interface can pass is 100 mbps, since it is a FE interface. but normally you dont see such huge traffic on any interfaces of PIX.
you can use the command show xlate or show conn to see the concurrent NAT connections on the PIX
Rate all replies if found useful.
11-08-2004 01:40 AM
also check
sh logging, these debugging level logs can have severe impact on the processor, depending on the volume of traffic trepassing pix.
packet debugs are also lethal in a production network, make sure you do
u all, on pix to disable any debugs running and eating up your cpu.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide