Re: [fw-wiz] PIX-515 acceptable CPU usage?

From: Brian Ford (
Date: 09/03/04

  • Next message: Robert McIntosh: "Re: [fw-wiz] Cisco PIX 501 Port Redirection Problem"
    To: "Adam Greene" <>
    Date: Fri, 03 Sep 2004 16:58:35 -0400


    You're definitely OK for now. Seems like at worst you'll see 20-25% CPU
    (10% base and 10% if you had 5 interfaces).

    You probably want to try and test a number of use cases including DoS'ing
    on of the less trusted interfaces or (and) establishing a couple of VPN or
    SSH sessions to the PIX and watching what happens.

    Chances are (without looking at your config or knowing how you use the PIX)
    you'll probably spike up to 60% when bad things happen.

    Liberty for All,


    At 02:22 PM 9/3/2004 -0400, wrote:
    >From: "Adam Greene" <>
    >To: <>
    >Date: Fri, 3 Sep 2004 11:47:17 -0400
    >Subject: [fw-wiz] PIX-515 acceptable CPU usage?
    >Hi --
    >We're deploying OSPF on our network for the first time, and it looks like it
    >will be convenient to enable OSPF on our PIX-515-UR's as well (running 6.3.3
    >OS). The problem
    >is, the moment I enable OSPF on the pixes, CPU usage on them shoots up from
    >0-1% to 7-10% (sh cpu usage). Each interface I add to area 0 appears to add
    >1-2% to CPU usage as well.
    >I've tried googling for acceptable CPU usage levels on the PIX, but came up
    >dry. Does anyone have a benchmark they can refer me to?
    >We're going to be passing about 5 Mbps through these pixes in the short term
    >(may grow to 10Mbps or higher). It would be nice to know that ongoing 15%
    >CPU usage is not going to cause noticeable performance degradation to our
    >users (we are broadband ISP).
    >Any input anyone may have is very welcome. Thanks for your help.
    >P.S. we're running 6.3.3 on the pixes

    Brian Ford
    Consulting Engineer, Security & Integrity Specialist
    Office of Strategic Technology Planning
    Cisco Systems Inc.

    The opinions expressed in this message are those of the author and not
    necessarily those of Cisco Systems, Inc..

    This email address is transmitted from San Jose, California, U.S.A..

    firewall-wizards mailing list

  • Next message: Robert McIntosh: "Re: [fw-wiz] Cisco PIX 501 Port Redirection Problem"

    Relevant Pages

    • Re: Yet another SVCHOST.EXE posting (my workaround)
      ... SVCHOST.EXE is an important part of Windows. ... Process Explorer you can see which and that is why I asked about the Command ... about the Windows Automatic Update service -a common cause of excessive CPU ... First off I killed PID 1302 and noticed that CPU usage fell down ...
    • Re: 99-100% Explorer Processor Usage
      ... Looking at a third incident on a separate PC of 'explorer.exe' hitting ... and see if the CPU is bogged down without the client installed. ... CPU usage hits 99-100% even where the PC has the custom application ... The tool expressly indicates the 'parent'/root 'Windows Explorer' is ...
    • Re: Does a Repair Install Affect Performance?
      ... I suggest you try cCleaner. ... CPU shot up to 80%+ for about 12 seconds while it started. ... > IE, iTunes, Microsoft Antispyware and Process Explorer itself. ... >>>> Sometimes CPU usage spikes when lots of apps open, ...
    • Re: Does a Repair Install Affect Performance?
      ... When the performance is poor check on CPU for unexplained activity. ... For further information about Process Explorer see here: ... >> Sometimes CPU usage spikes when lots of apps open, ... >>> One file suggests you have a Dell computer. ...
    • Terminal Server 2003 full CPU usage
      ... This almost regardles to the time the server is running. ... one process is maxing out at 80% to 99% CPU ... also RES Powerfuse has been installed. ... another process will take over full CPU usage. ...