We’re seeing a situation right now that seems to happen right before our firewall reboots itself. This is an ASA5540 running 8.2(1)11 code in an active/passive failover setup.
1. The firewalls CPU is around 50%, and is normally around 4%
2. The IPS modules CPU is stuck around 100% and inspection load stays around 70-90%, both are usually much lower
3. The firewall dashboard in ASDM shows a VPN connection as the source of most of the current traffic
4. When I do a “sh connection address” (and the address of the connection from the firewall dashboard), it shows it as currently being connected
5. If I try to clear the connection using the "clear connection" command, it does not clear
6. If I try to clear it using the "clear local-host" or "clear xlate" commands, it still will not clear the connection
7. If I manually failover the firewall, I can then clear the connection, manually fail it back over, and everything returns to normal
8. If I do nothing, the primary firewall will eventually reboot itself, failing over to the secondary unit and clearing the connection
Has anyone ever seen anything like this before? We're stumped and Cisco TAC hasn't been able to figure it out yet.