Guys I have been working with 3 IPS 2 4260 and a 4270 since yesterday I have noticed that the Inspection LOAD is RED. On the 4260 the inspection load is.
DCDetect1# sh statistics analysis-engine
Analysis Engine Statistics
Number of seconds since service started = 174759
The rate of TCP connections tracked per second = 0
The rate of packets per second = 4711
The rate of bytes per second = 8402
Total number of packets processed since reset = 823334516
Total number of IP packets processed since reset = 822979042
Total number of packets transmitted = 823478816
Total number of packets denied = 0
Total number of packets reset = 0
Fragment Reassembly Unit Statistics
Number of fragments currently in FRU = 0
Number of datagrams currently in FRU = 0
TCP Stream Reassembly Unit Statistics
TCP streams currently in the embryonic state = 0
TCP streams currently in the established state = 0
TCP streams currently in the closing state = 0
TCP streams currently in the system = 0
TCP Packets currently queued for reassembly = 0
The Signature Database Statistics.
Total nodes active = 16115
TCP nodes keyed on both IP addresses and both ports = 3438
UDP nodes keyed on both IP addresses and both ports = 29
IP nodes keyed on both IP addresses = 1715
Statistics for Signature Events
Number of SigEvents since reset = 153308490
For example in the 4270 we are passing almost nothing through the sensor... ANd its working in promiscuos mode. Why is the Inspection Load that High? In the 4260 is the same.. It is working in promiscuos mode.. There are alarms for missed packets as well.
I have been seeing several Discutions for the same reason but none has a fix. The Issue with the inspection load is random. DUring the day sometimes it high and sometimes is low.
Any advice will be really appreciated.