RE: [fw-wiz] PIX-515 acceptable CPU usage?

From: Eugene Kuznetsov (
Date: 09/16/04

  • Next message: Jim Seymour: "Re: [fw-wiz] About Port Forwarding, Apache and Firewall Rules"
    To: "'Ahmed, Balal'" <>, "'Adam Greene'" <>, <>
    Date: Thu, 16 Sep 2004 13:51:19 -0400

    > Some time ago cisco Documentation used to say that if your
    > PIX firewall is running at 30% sustained utilization then
    > an upgrade is advised. The latest

    It is worth noting that for many network device products, it is difficult
    for the vendor to provide a really accurate CPU utilization metric. There
    may be custom hardware assist, multiple processors, NPUs, and so on. It is
    not easy to reduce all of that to a single percentage.

    Also, such numbers are rarely linear. In other words, if a device is at 30%
    utilization right now, 2x more traffic won't drive it to 60% -- it may be
    40% or 100%, depending on the internal architecture.

    Some less ethical vendors will actually fudge their utilization metrics as a
    competitive tactic, i.e. "look, we're only at 5% utilization while
    saturating the network".

    So it's a useful basic health check, but be careful in placing too much
    trust in CPU utilization numbers, in PIX or elsewhere.

    \\ Eugene Kuznetsov, Chairman & CTO :
    \\ DataPower Technology, Inc. : Web Services security
    \\ : XML-aware networks

    firewall-wizards mailing list

  • Next message: Jim Seymour: "Re: [fw-wiz] About Port Forwarding, Apache and Firewall Rules"

    Relevant Pages

    • Re: Is onboard vidoe generally good enough?
      ... watching CBS using the Fusion software shows about 50% utilization, ... I believe the fusion software uses it's own decoder... ... > Since CPU utilization is highly dependent on CPU power/speed I do not know ...
    • SUMMARY: Correct %CPU usage
      ... matter of lying or not, it is just the way %CPU utilization is ... Single processes can be multi-threaded; ...
    • Re: performance counters on core-duo
      ... my application that I have migrated from a single to dual core machine. ... For the entire system my CPU utilization dropped about in half on the ... I make sense out of this by assuming that the system utilization is ...
    • Re: [fw-wiz] Firewall Utilization
      ... CPU utilization is sitting at about 60% right now, ... On Tue, 15 Oct 2002, Joe Keegan wrote: ... > After working with a few different companies firewalls, ...
    • Only one processor is in use... what AIX Does ????
      ... When i joined my new company tw weeks ago, i found one of the Lpar was ... working with 100% CPU utilization ... another processor into that Lpar using DLPAR and found that now CPU ... utilization was reduced to exactly 50%. ...