The problem we have is that the IPS is constantly at 100% CPU.
This is how the network is connected:
We have a 6500 on which we have a FWSM module and the default gateway for the FWSM (for internet) is on vlan 88.
This 6500 is then trunked to another switch. One of the ports on that switch is in vlan 88. That is where the IPS is connected and the other interface of the IPS goes to our outside ASA.
The other two interfaces of the IPS are connected on the other side of the ASA towards internet.
First thing I noticed is that the number of packets the IPS has received is huge.
When the CPU peeks there is a huge ammount of packets on the port where the IPS is connected na on the trunk betwean the 6500 and the other switch.
If i change something on the IPS (lets say modify any of the signatures) the CPU goes down and the number of packets on the trunk and on the port where the ips is cpnnected drops (around 100 packets/second). Then all of a sudden there is a storm of 10000-20000 packets per second and the IPS starts peeking the CPU at 100%.
I removed the interface pair from the sensor just to see wether something is going to change but it didn't. THe ips doesn't scan the traffic but the cpu started peeking again.
Currently the CPU is at 100%, inspection load is at 8%, System memory usage is at 47%, analysis engine memory is at 35%. Disk usage is also normal.
It seems that the IPS is creating some sort of a broadcast storm but I can't figure why.
Does anyone have an idea as to what might cause this?