cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1271
Views
0
Helpful
7
Replies

Upgraded ASA 5520 from 8.0.3 to 8.0.4.48 and memory up quite a bit

whiteford
Level 1
Level 1

Hello,

I have upgraded our 2 ASA firewalls (Active/Standby) from 8.0.3 to 8.0.4.48 and the memory has gone from 280mb to 450mb, the ASA's have 512mb.

Is this normal/ok?

I will call Cisco TAC on Monday, but seems quite a jump to me, I'm wondering if it has turned something on I don't need, not sure how I can check.

Thanks

7 Replies 7

plumbis
Level 7
Level 7

This is expected due to new features. I would suggest disabling threat-detection to free up some memory. As long as you aren't seeing a steady increase in memory I wouldn't sweat it.

How do I disable threat-detection?

to see what threat-detection features are enabled issue the command "show run threat-detection"

to disable those features use the "no" keyword before them.

For example

===========================

ciscoasa# sh run threat-detection

threat-detection basic-threat

threat-detection statistics access-list

ciscoasa# conf t

ciscoasa(config)# no threat-detection basic-threat

ciscoasa(config)# no threat-detection statistics access-list

===========================

Thanks,

I tried that but made no difference to the amount of memory being used, how can I show what is taking it all up?

You can try show proc mem.

HTH,

jerry

This is what it shows:

The top two offenders are tmatch compile and dispatch unit. tmatch compile is related to ACLs and dispatch unit related to traffic.

How big are your access lists? (show access-list | i elements)

What is the platform?

How much traffic is going through this box?

Are there drops, errors, overruns or underruns on the interfaces?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card