High CPU in Cisco IPS

The below information will help to identify/fix the High CPU Utilization if noticed in the Cisco IPS device.

1. execute the command sh statistics virtual-sensor in CLI
2. analyse the inspection load from the output and other related informations
3. execute sh interface to see the fifo/overrun errors
4. capture the logs/events
5. identify which signature is maximum seen
6. locate the source ip/hosts
7. isolate the source from the network
8. scan/investigate the source for any attempts/virus/botnets

if you are looking for workaround

reboot the box and try to see the performance now

if you stuck-up and dont know what to do

capture the sh tech output and provide it to TAC

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Blog at WordPress.com.

Up ↑

%d bloggers like this: