CISCO IPS 4260 CPU USAGE 99%
Hi guys
I'm detecting something unusual on my CISCO IPS 4260. This device have 2 CPU's but only in one cpu is showing 99% of use, and the inspection load varies from 40 to 50, and sometimes 80, here's a screenshot of what I'm talking about.
Where can I start to troubleshoot why is showing this values.?
Regards.
do you think is normal that the IPS signature with more hits is de SIGID 5575 (NBT NetBIOS Session Service Failed Login?
After doing some research it seems to be normal for a windows enviroment.
Here is the information I got
Description
When a client connects to a SMB server (WinNT, Win95, Samba, etc..) a TCP connection to port 139 is established. The client then provides the server with its NetBIOS name and the NetBIOS name it wishes to connect to. If the name does not exist on the server, the session setup attempt fails and an error message is sent to the client. This could be an indicator of an attack.
Recommended Filter
Exclude internal networks as sources.
Benign Triggers
The default alarm level for this is low because this happens during normal network activity within a Windows network. As an example, when mounting the C: drive from a Windows 95 system to a Windows NT system, numerous session setup failures can occur while browsing the file system.
As you can see you could excluded to stop triggering that, this is an informational signature
Regards,
Remember to rate all of the helpful posts
Similar Messages
-
hi!
we have installed two cisco ips 4260 in our test environment and want now to monitor the inspection load, which is from my point of view much more important than the cpu load, with the open source network tool cacti. I want to send alerts when a specific threshold has exceeded.
I already monitor the cpu load, the interfaces with snmp. Do you know if it is possible to get the value of the inspection load of the ips by snmp?
Which others parameters of the ips sensors are important to monitor?
Thanks!!!At this time the sensor's inspection load is not exposed via a SNMP OID. There is an enhancement request to add SNMP monitoring of various sensor health metrics in a future release.
Thanks,
Scott -
Cisco ips 4270 cpu 100% utilization...
hi folks i have cisco ips 4270 version 7.0(2) E3 when i try to access it through IDM its show the cpu utilization of cpu1=100% and cpu4=100% but cpu1 and cpu2 are varying can any one please tell me what will be the solution of this problem...
when i try to go to the configuration then its give me the attached error..........document attached please check....Hi,
Having 100% on some of your CPU is normal on the IPS platform.
The device is using it's idle cycles to prepare for the handling of the incoming packets and to reduce the delay it will introduce on their path so it is expected to get this even when under low load.
If you want to have a better idea of the capacity % of your IPS you are currently using, you should have a look at the Inspection Load value. Looking at the data you provided, you are around 25% at the moment.
For the rdep timeout message, it seems to be a software issue. Looking closer at the picture you attached, we also see "Analysis Engine Status: Not Responding".
It is a bit difficult to troubleshoot those on CSC so I would advise you to open a TAC case if you want to know the exact root cause.
What I would advise is to upgrade to the latest 7(0) code which is I believe 7.0(5a)E4 since the issue is most then likely fixed in this version.
If you are looking for a quick fix, a reboot of the IPS should clear this but the problem will most then likely come back later.
Regards,
Nicolas -
Cisco IPS 4260 Can't login to IDM after upgrade to 7.1(9)
Hi,
I recently upgraded my 4260 sensor to 7.1(9). Before the upgrade, I could log-in to the sensors via the IDM (JNLP). Now after the upgrade, the IDM prompt comes up but when I enter my username and password, I get a pop saying "Unable to launch device manager from https://[x.x.x.x]"
On viewing the detailed logs, I get java.net.MalformedURLException: Invalid host: [x.x.x.x]. The same error is repeated multiple times.
I also get messages like "Trying for IDM. url=https://[x.x.x.x]/idm/idm.jnlp/
To me it seems that the program is unnecessarily adding the "[ ]" to the host and this is causing the url to fail.
I have downloaded a fresh copy of jnlp file from the updated sensor. My java version is 7Update51. This version worked correctly with the idm.jnlp supplied with the previous sensor update 7.1(8).
Cisco IME 7.2.3 can correctly connect to the sensor and I can also login via SSH using the same username and password.
Has anyone faced a similar issue? Is there a solution?
ThanksHave you solved your problem? I think I have the same issue.
-
Hello, friends.
There are Cisco (C2801-ADVENTERPRISEK9_IVS-M), Version 15.1 (4) M7.
Telephones connected to SCCP. There is one trunk with a SIP-provider.
about two weeks there were no problems. Since yesterday in error logs:
Jun 25 17:31:07.019: %IVR-3-LOW_CPU_RESOURCE: IVR: System experiencing high cpu utilization (97/100).
Call (callID=190) is rejected.
Jun 25 17:31:11.799: %IVR-3-LOW_CPU_RESOURCE: IVR: System experiencing high cpu utilization (97/100).
Call (callID=191) is rejected.
Jun 25 17:31:28.443: %IVR-3-LOW_CPU_RESOURCE: IVR: System experiencing high cpu utilization (97/100).
Call (callID=192) is rejected.
Jun 25 17:33:16.403: %IVR-3-LOW_CPU_RESOURCE: IVR: System experiencing high cpu utilization (97/100).
Call (callID=195) is rejected.
Jun 25 17:34:12.059: %IVR-3-LOW_CPU_RESOURCE: IVR: System experiencing high cpu utilization (97/100).
Call (callID=197) is rejected.
Jun 25 17:35:53.335: %IVR-3-LOW_CPU_RESOURCE: IVR: System experiencing high cpu utilization (97/100).
Call (callID=198) is rejected.
DC(config)# do show proc cpu sort
CPU utilization for five seconds: 98%/54%; one minute: 94%; five minutes: 96%
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
127 4265972 410671 10387 31.06% 28.33% 26.47% 0 IP Input
7 1073688 374129 2869 6.96% 6.33% 5.85% 0 Pool Manager
84 122676 17048 7195 2.56% 0.79% 0.72% 0 Skinny Msg Serve
383 89324 17955 4974 0.95% 0.69% 0.66% 0 IP NAT Ager
64 8928 273 32703 0.79% 0.09% 0.06% 0 Per-minute Jobs
287 16476 5739 2870 0.31% 0.08% 0.07% 0 Crypto PAS Proc
103 88684 349633 253 0.31% 0.42% 0.37% 0 Ethernet Msec Ti
173 12576 5995 2097 0.31% 0.09% 0.07% 0 TCP Timer
172 3588 110 32618 0.31% 0.03% 0.00% 0 Licensing Auto U
318 23992 3777 6352 0.23% 0.10% 0.05% 194 SSH Process
how to diagnose where the problem?
On the external interface acl:
Extended IP access list FW-OUT
10 permit icmp any any (1279 matches)
20 permit tcp any host 92.63.108.115 eq 22 (1599 matches)
30 permit gre host 217.197.126.52 host 92.63.108.115
40 permit esp host 217.197.126.52 host 92.63.108.115 (3616549 matches)
50 permit udp host 217.197.126.52 host 92.63.108.115 eq isakmp (3 matches)
60 permit esp any host 92.63.108.115 (1505 matches)
70 permit udp any host 92.63.108.115 eq isakmp (26 matches)
80 permit udp any host 92.63.108.115 eq non500-isakmp (28062 matches)
90 permit tcp any host 92.63.108.115 eq www
100 permit tcp any host 92.63.108.115 eq ftp ftp-data
110 permit gre host 46.165.197.108 host 92.63.108.115 (39348 matches)
120 permit tcp any host 92.63.108.115 eq 1723
130 permit gre any host 92.63.108.115
140 permit ip host 217.150.198.44 host 92.63.108.115
150 permit ip host 178.63.96.3 host 92.63.108.115
160 permit ip host 78.46.95.118 host 92.63.108.115
170 permit ip host 176.9.145.115 host 92.63.108.115 (79 matches)
180 permit ip host 176.9.85.133 host 92.63.108.115
190 permit ip host 5.9.108.25 host 92.63.108.115
200 permit ip host 89.249.23.194 host 92.63.108.115 (156 matches)
210 permit ip host 46.4.53.86 host 92.63.108.115
220 permit ip host 5.9.84.165 host 92.63.108.115
230 permit ip host 144.76.42.108 host 92.63.108.115 (141 matches)
240 permit ip host 178.16.26.122 host 92.63.108.115
250 permit ip host 178.16.26.124 host 92.63.108.115
260 permit ip host 178.63.96.28 host 92.63.108.115
350 deny ip any any (805 matches)Hi,
1) looking at the error message decoder
The alarm generates the following output:-
%IVR-3-LOW_CPU_RESOURCE: IVR: System experiencing high cpu utilization ([dec]/100). Call (callID=[dec]) is rejected.\n
The system does not have enough CPU resources available to accept a new call.
Recommended Action: Ensure that the call setup rate is within the supported capacity of this gateway.
Related documents- No specific documents apply to this error message.
2) Have a read at this link re High CPU - IP INPUT
http://www.cisco.com/c/en/us/support/docs/routers/7500-series-routers/41160-highcpu-ip-input.html
Regards
Alex -
Cisco SA540 100% CPU usage
Hi,
We've implemented one Cisco SA540 for SSL VPN only, no routing function. However, the unit always be hang after 26, 27 days used although there are no user connected. And I only can access to the SA540 through LAN interface, the WAN interface cannot access.
Wwe've contacted with Cisco support, try upgrade to the latest firmware 2.2.0.7, also replace the new unit, but the problem still happen.
So, any advice for this case.
Thank you so much
Regards,
KevinDear Kevin,
Thank you for reaching the Small Business Support Community.
Could you please screenshot the VPN and IKE Policies so that we can check it out? Is there a Cisco support case currently opened? If so, please add the case number so I can follow the progress on it.
I'll be looking forward to your reply.
Kind regards,
Jeffrey Rodriguez S. .:|:.:|:.
Cisco Customer Support Engineer
*Please rate the Post so other will know when an answer has been found. -
Does anybody know how to export the events log from a IPS 4260 ?
My company has a Cisco IPS 4260 and we used to get the log from the Cisco Security Manager but since July the software failed and now (December) I need to get / export the log from July to December that I think it is saved into the IPS. Is it possible? Does anybody know the command to see the saved log or the commands or procedure to export the log into a TFTP or FTP ?
I'll really appreciate your help, thanks.No; That cannot be done. Only through a SDEE server.
Events are stored on a hard drive that the IPS has, if it has not been reloaded they should be there with no issues.
Get the application "IME". If I am not mistaken, you would be able to see those events there and I think there is a way to export them from there.
Mike Rojas -
Error: Cannot connect to NTP server or NTP server is not running - Cisco IPS
This is different scenario here:
I have two Cisco IPS 4260-k9 and both are in production now.
One of the IPSs is configured with NTP and works fines, but another one is not.
When tried to configure when the device is ON and live in production and got the following error,
Error from CLI:
" Error: Cannot connect to NTP server or NTP server is not running "
Error from IME:
" Delivery failed.
err Unaccepable Value - cannot connect to the NTP server or NTP server is not running"
I am able to reach the NTP server, also the same NTP is working fine with other devices....
Am I doing anything wrong?
Please adviseHi,
Now the error has changed:
Session.connect: java.net.SocketTimeoutException: Read timed out
I have increased the pooling interval to 1 Hr from 1 Min. Waiting for the next pooling interval result.
Guide me if I am heading right.... or anything else needs to be done.
Regards,
Krishna Chauhan -
User account to download Cisco IPS signature
Hi All,
I wanted to enable the Autoupdate in IPS but it asks for Cisco acc with cryptographic privileges to download Cisco IPS signature and signature engine updates from Cisco.com.
is their any default acc for this ?
I have CCO acc whether is this can be used ?
You must have a Cisco.com user account with cryptographic privileges to download Cisco IPS signature and signature engine updates from Cisco.com.Using your cisco.com account go to this link and see if you can download the IPS-K9-6.1-2-E3.pkg file to your own desktop machine.
http://tools.cisco.com/support/downloads/go/ImageList.x?relVer=6.1%282%29E3&mdfid=280302728&sftType=Intrusion+Prevention+System+%28IPS%29+System+Upgrades&optPlat=&nodecount=2&edesignator=null&modelName=Cisco+IPS+4260+Sensor&treeMdfId=278875311&treeName=Intrusion+Prevention+System+%28IPS%29&modifmdfid=null&imname=&hybrid=Y&imst=N&lr=Y
If you can download this file with your account, then you can use that account and password when configuring the sensor for the cisco.com automatic upgrades.
If you can not download the file with your account, then your account does not have the right settings.
Either your account does not have crypto access or your account is not properly linked to your service contract for your sensors.
There are a handfull of countries not allowed to have crypto access, users from all other countries would just need to get their account modified for crypto access (I am not sure what that procedure is). -
Cisco ips 4270 unequal cpu utilization
I am having 2 cisco IPS 4270 devices with an IOS version 7.0(2)E4. When monitoring through IPS manager, I am able to see 4 CPU's.
In CPU 1 the utilzation is showing near to 100 percent. CPU 2 is showing zero or very less utilsation. CPU 3 & CPU 4 are showing average utilization - nearly equal to 40 percent.
I doubt why i am getting zero percent CPU utilization in CPU 2 and 100 percent utilisation in CPU 1?
whether we can do a distribution of CPU among the four CPU's.?
Hey cisco folks, please help.This was mentioned in a previous post, specifically the reply by Scott Fringer. Post here:
https://supportforums.cisco.com/message/3065777#3065777
In Scott's post, he quoted the E3 engine release notes regarding CPU utilization (highlighting mine):
The E3 signature engine update contains changes from CSCsu77935
The resolution of this defect modified the idle time algorithm of the sensor by applying additional CPU to polling of the NICs to decrease the polling interval and reduce latency. This results in the CPU usage being reported higher than in previous releases, including using external tools such as top and ps.
You can notice this additional CPU load on single-CPU platforms, as well as the primary CPU of multi-core systems. Since the additional CPU load that is reported while polling is actually available to process packets, and reduces as inspection load goes up, it does not negatively affect the overall throughput of the IPS.
So, what you are seeing should be considered normal, and doesn't need correction. That is, unless you are seeing packet loss. -
I'm in the process of studying for my CCNA Security and just finished the section about IDS and IPS. I knew about them before, but didn't know that they could be configured on a standard ISR through the SDM. I have a 2811 as our main router, then goes out to our ASA and then to our WAN router. If I implement IPS on my main 2811 router without the network modules or aim cards, about how much cpu usage does it us? Is it going to greatly slow down our network, or will I really even notice?
On the 2811, we have 2 point to point T1's, and does all the main routing. Will having IPS run off the same CPU slow down my network? Or would it be best to look into the AIM module, or something else?Do not enable all IPS signatures. The router may not be able to able to compile all signatures, resulting in high CPU and memory usage, degraded performance, and a system crash.
http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ips_v5.html#wp1093849 -
Hi guys
I got a problem with an IPS, from some weeks the CPU has been at 100% (all the 4 CPU's) and I don't know why, the Inspection Load is really low and I guess this is not affecting to this. Here some information of the SHOW VERSION command
*I also attach some images of the IPS*
Cisco Intrusion Prevention System, Version 7.1(1)E4
Host:
Realm Keys key1.0
Signature Definition:
Signature Update S807.0 2014-06-13
OS Version: 2.6.29.1
Platform: ASA5585-SSP-IPS10
Using 4428M out of 5839M bytes of available memory (75% usage)
system is using 25.1M out of 160.0M bytes of available disk space (16% usage)
application-data is using 68.0M out of 171.6M bytes of available disk space (42% usage)
boot is using 56.0M out of 70.5M bytes of available disk space (84% usage)
application-log is using 494.0M out of 513.0M bytes of available disk space (96% usage)
I hope somebody had some idea what could be causing the high cpu usage.
RegardsHas this been something that just recently started happening, or have you had this issue for a while? Have you installed any new programs recently?
You may want to download Glary Utilities, which is a free software(they will ask you if you want to go Pro, just say no, the free version works very well). There is a module for startup manager. You can go in and disable stuff that starts with the computer. I would advise unchecking adobe, java, quicktime, printers, etc. Anything that doesn't REALLY need to start with the computer. The nice thing with Glary is that you can restart the computer, and if you find that you need one of the programs to start with windows, you can go back in and enable it again.
The Celeron 925 processor in your computer is a decent entry level processor, but if there are too many programs running in the background, it can bog down quick. I would also recommend downloading and running Malwarebytes Anti-malware, to be sure that there is nothing malicous running in the background.
Qosmio X875 i7-3630QM, 32GB RAM, OCZ SSD Qosmio X505 i7-920XM, PM55, 16GB RAM, OCZ SSD
Satellite Pro L350 T9900, GM45, 8GB RAM , Intel 320 SSD (my baby) Satellite L655 i7-620M, HM55, 8GB RAM, Intel 710 SSD (travel system) -
Hi all,
I'm having high CPU usage with one of my Cisco 3845.
It works as an IP-IP Gateway and the CPU is quite high when the total number of calls only around 100-200 calls.
I check the CPU usage with "show process cpu sort" and it looks like there are some "hidden" processes that consuming CPU.
For example, 41% is total CPU, 25% is due to interrups, so CPU utilization on process level = 41 - 25 = 16%.
But as showed below, processes don't consume that much CPU, only around 7% ???
Please help to advise on this case. Any help is highly appreciated..
Thank you.
3845-GW#show process cpu sort | ex 0.00% 0.00% 0.00%
CPU utilization for five seconds: 41%/25%; one minute: 46%; five minutes: 47%
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
382 6619708 1473171 4493 1.59% 1.81% 1.92% 0 CCSIP_SPI_CONTRO
141 4228940 10181955 415 1.35% 1.51% 1.57% 0 IP Input
65 2450824 163102 15026 1.19% 1.16% 1.17% 0 Per-Second Jobs
370 2702292 3709512 728 0.87% 0.88% 0.88% 0 VOIP_RTCP
224 321680 245640 1309 0.47% 0.49% 0.50% 0 AFW_application_
112 93940 18093506 5 0.39% 0.31% 0.32% 0 Ethernet Msec Ti
384 1058280 1553567 681 0.23% 0.28% 0.30% 0 CCSIP_UDP_SOCKET
2 18148 32905 551 0.07% 0.03% 0.02% 0 Load Meter
137 35644 4657843 7 0.07% 0.04% 0.05% 0 IPAM Manager
189 206392 267959 770 0.07% 0.05% 0.07% 0 TCP Protocols
30 30792 198554 155 0.07% 0.01% 0.00% 0 ARP Input
368 145456 176151 825 0.07% 0.04% 0.05% 0 CC-API_VCM
28 9628 32759 293 0.00% 0.01% 0.00% 0 Environmental mo
48 221352 37922 5837 0.00% 0.11% 0.11% 0 Net Background
63 16728 32924 508 0.00% 0.01% 0.00% 0 Compute load avg
64 72080 2781 25918 0.00% 0.01% 0.00% 0 Per-minute Jobs
6 371644 29792 12474 0.00% 0.14% 0.12% 0 Check heaps
176 12216 240288 50 0.00% 0.01% 0.00% 0 CEF: IPv4 proces
284 36416 4929826 7 0.00% 0.02% 0.01% 0 MMON MENG
307 12168 806151 15 0.00% 0.01% 0.00% 0 Atheros LED Ctro
335 35300 19755 1786 0.00% 3.16% 1.00% 708 Virtual Exec
3845-GW#sh int g0/0
GigabitEthernet0/0 is up, line protocol is up
MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full Duplex, 1Gbps, media type is RJ45
output flow-control is XON, input flow-control is XON
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/2/56803 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 1551000 bits/sec, 5751 packets/sec
5 minute output rate 4207000 bits/sec, 7643 packets/sec
925128804 packets input, 939078510 bytes, 0 no buffer
Received 62732 broadcasts (0 IP multicasts)
0 runts, 0 giants, 2 throttles
2 input errors, 0 CRC, 0 frame, 2 overrun, 0 ignored
0 watchdog, 3763438515 multicast, 0 pause input
1472816545 packets output, 3214770103 bytes, 0 underruns
0 output errors, 2067720191 collisions, 1 interface resets
0 unknown protocol drops
0 babbles, 2281155551 late collision, 0 deferred
2 lost carrier, 0 no carrier, 0 pause output
0 output buffer failures, 0 output buffers swapped out
3845-GW#sh int g0/1
GigabitEthernet0/1 is up, line protocol is up
MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full Duplex, 1Gbps, media type is RJ45
output flow-control is XON, input flow-control is XON
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/30335 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 1684000 bits/sec, 7697 packets/sec
5 minute output rate 3372000 bits/sec, 5632 packets/sec
1484558664 packets input, 2383177786 bytes, 0 no buffer
Received 208998 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
2 input errors, 0 CRC, 0 frame, 2 overrun, 0 ignored
0 watchdog, 3060386282 multicast, 0 pause input
903478941 packets output, 2814588854 bytes, 0 underruns
0 output errors, 2910776303 collisions, 1 interface resets
0 unknown protocol drops
0 babbles, 4157448025 late collision, 0 deferred
2 lost carrier, 0 no carrier, 0 pause output
0 output buffer failures, 0 output buffers swapped outHas this been something that just recently started happening, or have you had this issue for a while? Have you installed any new programs recently?
You may want to download Glary Utilities, which is a free software(they will ask you if you want to go Pro, just say no, the free version works very well). There is a module for startup manager. You can go in and disable stuff that starts with the computer. I would advise unchecking adobe, java, quicktime, printers, etc. Anything that doesn't REALLY need to start with the computer. The nice thing with Glary is that you can restart the computer, and if you find that you need one of the programs to start with windows, you can go back in and enable it again.
The Celeron 925 processor in your computer is a decent entry level processor, but if there are too many programs running in the background, it can bog down quick. I would also recommend downloading and running Malwarebytes Anti-malware, to be sure that there is nothing malicous running in the background.
Qosmio X875 i7-3630QM, 32GB RAM, OCZ SSD Qosmio X505 i7-920XM, PM55, 16GB RAM, OCZ SSD
Satellite Pro L350 T9900, GM45, 8GB RAM , Intel 320 SSD (my baby) Satellite L655 i7-620M, HM55, 8GB RAM, Intel 710 SSD (travel system) -
Hi All,
I have a cisco 2811 that is high in CPU usage. Below is my IOS version and process usage details.
Cisco IOS Software, 2800 Software (C2800NM-IPBASEK9-M), Version 12.4(24)T4, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Fri 03-Sep-10 05:39 by prod_rel_team
ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
ipscape-myob uptime is 6 weeks, 5 days, 17 hours, 18 minutes
System returned to ROM by reload at 10:33:59 UTC Thu Apr 10 2014
System image file is "flash:c2800nm-ipbasek9-mz.124-24.T4.bin"
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
[email protected].
Cisco 2811 (revision 53.51) with 514048K/10240K bytes of memory.
Processor board ID FHK1238F1D4
2 FastEthernet interfaces
DRAM configuration is 64 bits wide with parity enabled.
239K bytes of non-volatile configuration memory.
62720K bytes of ATA CompactFlash (Read/Write)
Configuration register is 0x2102
CPU utilization for five seconds: 90%/77%; one minute: 79%; five minutes: 76%
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
8 20693808 28614857 723 7.67% 1.24% 0.44% 0 IP SLAs Respond e
91 13460456 18459988 729 3.27% 0.67% 0.31% 0 IP Input
143 3167640 1026953957 3 1.19% 1.62% 1.68% 0 HQF Shaper Back g
184 809676 128826693 6 0.39% 0.38% 0.39% 0 PPP manager
196 1072 112 9571 0.31% 0.23% 0.06% 514 Virtual Exec
185 771340 128826711 5 0.23% 0.18% 0.16% 0 PPP Events
Could you please provide me some info on this issues.
Thank You!Has this been something that just recently started happening, or have you had this issue for a while? Have you installed any new programs recently?
You may want to download Glary Utilities, which is a free software(they will ask you if you want to go Pro, just say no, the free version works very well). There is a module for startup manager. You can go in and disable stuff that starts with the computer. I would advise unchecking adobe, java, quicktime, printers, etc. Anything that doesn't REALLY need to start with the computer. The nice thing with Glary is that you can restart the computer, and if you find that you need one of the programs to start with windows, you can go back in and enable it again.
The Celeron 925 processor in your computer is a decent entry level processor, but if there are too many programs running in the background, it can bog down quick. I would also recommend downloading and running Malwarebytes Anti-malware, to be sure that there is nothing malicous running in the background.
Qosmio X875 i7-3630QM, 32GB RAM, OCZ SSD Qosmio X505 i7-920XM, PM55, 16GB RAM, OCZ SSD
Satellite Pro L350 T9900, GM45, 8GB RAM , Intel 320 SSD (my baby) Satellite L655 i7-620M, HM55, 8GB RAM, Intel 710 SSD (travel system) -
High CPU usage in cisco 7613 with rsp720-3cxl
Hi everybody,
our cisco 7613 has about 4.5 Gbps Tx/Rx IP traffic in total, and we run ospf with other cisco cloud for routing I list in the following some our router show.what is your idea about our high cpu usage .Is it in normal range with the listed cards and modules.How can I tune the rsp720 and other SIP-200,400,600 for better performances
why our interrupt rate is high ,and one thing more the total sum of 5sec in separate rows not equal to cpu utilization for five second 50%
show proc cpu sor
CPU utilization for five seconds: 50%/46%; one minute: 54%; five minutes: 59%
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
8 196795220 12640741 15568 1.51% 0.38% 0.26% 0 Check heaps
224 1048610528 4169501364 0 1.19% 1.45% 1.44% 0 IP Input
13 374006320 3155162661 0 0.23% 0.26% 0.24% 0 ARP Input
217 119862004 985030884 121 0.15% 0.32% 0.25% 0 ADJ resolve pro
c
185 537716 1825736183 0 0.07% 0.03% 0.02% 0 ACE Tunnel Task
260 1550992 2983272818 0 0.07% 0.13% 0.15% 0 Ethernet Msec T
i
305 38186336 58050485 657 0.07% 0.02% 0.00% 0 XDR mcast
34 67208 11707798 5 0.07% 0.00% 0.00% 0 IPC Loadometer
27 232776 57160812 4 0.07% 0.01% 0.00% 0 IPC Periodic Ti
m
325 17539200 92894502 188 0.07% 0.15% 0.15% 0 CEF: IPv4 proce
s
195 7406636 43782487 169 0.07% 0.00% 0.00% 0 esw_vlan_stat_p
r
show ip route summ
IP routing table name is default (0x0)
IP routing table maximum-paths is 32
Route Source Networks Subnets Replicates Overhead Memory (bytes)
static 1 120 0 7620 20812
connected 0 313 0 18860 53836
ospf 98 17 4892 0 589020 863984
Intra-area: 89 Inter-area: 383 External-1: 0 External-2: 0
NSSA External-1: 0 NSSA External-2: 4437
bgp 12880 0 1 0 60 172
External: 1 Internal: 0 Local: 0
ospf 410 0 269 0 16220 47344
Intra-area: 1 Inter-area: 0 External-1: 0 External-2: 268
NSSA External-1: 0 NSSA External-2: 0
internal 137 260544
Total 155 5595 0 631780 1246692
sh module
Mod Ports Card Type Model Serial No.
1 0 4-subslot SPA Interface Processor-200 7600-SIP-200
2 0 4-subslot SPA Interface Processor-400 7600-SIP-400
3 24 CEF720 24 port 1000mb SFP WS-X6724-SFP
6 1 1-subslot SPA Interface Processor-600 7600-SIP-600
7 2 Route Switch Processor 720 (Active) RSP720-3CXL-GE
8 2 Route Switch Processor 720 (Cold) RSP720-3CXL-GE
show ver
System image file is "bootdisk:c7600rsp72043-adventerprisek9-mz.122-33.SRE2.bin"
1 SIP-200 controller .
1 SIP-400 controller (1 Channelized OC3/STM-1).
1 SIP-600 controller (1 TenGigabitEthernet).
2 Virtual Ethernet interfaces
28 Gigabit Ethernet interfaces
1 Ten Gigabit Ethernet interface
1 Channelized STM-1 port
1 Channelized STM-1 port
show int vlan 1
Encapsulation ARPA, loopback not set
Keepalive not supported
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters 2d23h
Input queue: 0/75/2886/1830 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 2380531000 bits/sec, 287383 packets/sec
5 minute output rate 422133000 bits/sec, 254113 packets/sec
L2 Switched: ucast: 1200869468 pkt, 101172643240 bytes - mcast: 253599 pkt, 78
873415 bytes
L3 in Switched: ucast: 60947040633 pkt, 68919665115039 bytes - mcast: 0 pkt, 0
bytes mcast
L3 out Switched: ucast: 52594517004 pkt, 9869168832783 bytes mcast: 0 pkt, 0 b
ytes
62147839148 packets input, 69016175499764 bytes, 0 no buffer
Received 257634 broadcasts (0 IP multicasts)
0 runts, 0 giants, 15 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
53647248858 packets output, 10292998021217 bytes, 0 underruns
0 output errors, 0 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped outThank you for your hints and replying
These are our show ibc in 1 min interval
Interface information:
Interface IBC0/0
5 minute rx rate 20045000 bits/sec, 30183 packets/sec
5 minute tx rate 47394000 bits/sec, 60212 packets/sec
19879272237 packets input, 4006174536193 bytes
19835355282 broadcasts received
19808585787 packets output, 3981305571968 bytes
90548 broadcasts sent
0 Bridge Packet loopback drops
19756362091 Packets CEF Switched, 1320184 Packets Fast Switched
0 Packets SLB Switched, 0 Packets CWAN Switched
Label switched pkts dropped: 0 Pkts dropped during dma: 339549
Invalid pkts dropped: 0 Pkts dropped(not cwan consumed): 0
IPSEC pkts dropped: 635184
Xconnect pkts processed: 0, dropped: 0
Xconnect pkt reflection drops: 0
Total paks copied for process level 0
Total short paks sent in route cache 2605317676
Total throttle drops 265338 Input queue drops 5831090
total spd packets classified (120217214 low, 174503 medium, 3073 high)
total spd packets dropped (339549 low, 0 medium, 0 high)
spd prio pkts allowed in due to selective throttling (0 med, 0 high)
IBC resets = 1; last at 23:52:49.004 Sat Jan 19 2013
Driver Level Counters: (Cumulative, Zeroed only at Reset)
Frames Bytes
Rx(0) 26537712 3421085217
Rx(1) 3449063135 2838813650
Tx(0) 3390340306 2016620276
Input Drop Frame Count
Rx0 = 0 Rx1 = 2488435
Per Queue Receive Errors:
FRME OFLW BUFE NOENP DISCRD DISABLE BADCOUNT
Rx0 0 0 0 0 0 0 0
Rx1 0 0 0 3633 0 0 0
Tx Errors/State:
One Collision Error = 0 More Collisions = 0
No Encap Error = 0 Deferred Error = 0
Loss Carrier Error = 0 Late Collision Error = 0
Excessive Collisions = 0 Buffer Error = 0
Tx Freeze Count = 0 Tx Intrpt Serv timeout= 1
Tx Flow State = FLOW_ON
Tx Flow Off Count = 0 Tx Flow On Count = 0
Counters collected at Idb:
Is input throttled = 0 Throttle Count = 0
Rx Resource Errors = 0 Input Drops = 2488435
Input Errors = 194243
Output Drops = 0 Giants/Runts = 0/0
Dma Mem Error = 0 Input Overrun = 0
Hash match table for multicast (in use 0, maximum 64 entries):
show ibc
Interface information:
Interface IBC0/0
5 minute rx rate 20194000 bits/sec, 30412 packets/sec
5 minute tx rate 47753000 bits/sec, 60663 packets/sec
19891125514 packets input, 4007158118761 bytes
19847185365 broadcasts received
19820407164 packets output, 3982279276274 bytes
90576 broadcasts sent
0 Bridge Packet loopback drops
19768178233 Packets CEF Switched, 1321008 Packets Fast Switched
0 Packets SLB Switched, 0 Packets CWAN Switched
Label switched pkts dropped: 0 Pkts dropped during dma: 339549
Invalid pkts dropped: 0 Pkts dropped(not cwan consumed): 0
IPSEC pkts dropped: 635574
Xconnect pkts processed: 0, dropped: 0
Xconnect pkt reflection drops: 0
Total paks copied for process level 0
Total short paks sent in route cache 2606549061
Total throttle drops 265338 Input queue drops 5831090
total spd packets classified (120252754 low, 174531 medium, 3074 high)
total spd packets dropped (339549 low, 0 medium, 0 high)
spd prio pkts allowed in due to selective throttling (0 med, 0 high)
IBC resets = 1; last at 23:52:49.004 Sat Jan 19 2013
Driver Level Counters: (Cumulative, Zeroed only at Reset)
Frames Bytes
Rx(0) 26550723 3422835145
Rx(1) 3461063605 176652699
Tx(0) 3402319442 3368513724
Input Drop Frame Count
Rx0 = 0 Rx1 = 2490155
Per Queue Receive Errors:
FRME OFLW BUFE NOENP DISCRD DISABLE BADCOUNT
Rx0 0 0 0 0 0 0 0
Rx1 0 0 0 3633 0 0 0
Tx Errors/State:
One Collision Error = 0 More Collisions = 0
No Encap Error = 0 Deferred Error = 0
Loss Carrier Error = 0 Late Collision Error = 0
Excessive Collisions = 0 Buffer Error = 0
Tx Freeze Count = 0 Tx Intrpt Serv timeout= 1
Tx Flow State = FLOW_ON
Tx Flow Off Count = 0 Tx Flow On Count = 0
Counters collected at Idb:
Is input throttled = 0 Throttle Count = 0
Rx Resource Errors = 0 Input Drops = 2490155
Input Errors = 194358
Output Drops = 0 Giants/Runts = 0/0
Dma Mem Error = 0 Input Overrun = 0
Hash match table for multicast (in use 0, maximum 64 entries):
and sorry what is your idea about total sum of 5sec in separate rows not equal to cpu utilization for five second 50%
Maybe you are looking for
-
Replace hard drive and windows 8 software
I want to order a new hard ddrive (640 GB) and replace software and drivers. I found a replcement order for $30+ to replace drivers and software for windows 8. Am I getting the new software to replace the information on a new hard drive, or do I hav
-
Disk utility. start up disk
Trying to run disk utility from the start up disk. I insert install disk #1. Restart while pressing C key. I just get the language thing then the installer. There is no disk utility or installer menu. If I press continue, it's a dead end only install
-
In this video 12 sec in what is the app they use?
http://www.apple.com/ipad/#doitall can you please help me..
-
Can the iPad support a dongle for wifi access?
Can anyone tell me if this is possible and what the solution is?
-
Pictures in iMessage...
I cannot send pictures using iMessage or MMS to just 1 contact. Can anybody provide a clue as to why or a solution?? Have tried all sorts to resolve but no joy!