cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9092
Views
40
Helpful
33
Replies

security intelligence URL: memcap exceeded Alert in FMC related to one firepower module

engahmedsaied
Level 1
Level 1

Hello all,

 

after upgrading to version 6.2.2 we face the following error 

 

security intelligence URL: memcap exceeded

 

also same error exist in 6.2.2.1

 

I saw similar bug but on FTD, we are not using FTD

 

we are using one virtual firepower management center to manage two ASAs with firepower module.

33 Replies 33

All good questions.

I just don’t know the answer to that one! ☺


Todd,

 

How is it you can see how many objects are being loaded?

Thx, I get this message on a ASA 5512X (with 6.2.3)

 

TCSPB
Level 1
Level 1

Cisco has a hotfix out for this.  We received it from TAC and I installed it today and all issues with the errors are resolved. 

 

I suggest opening a case with Cisco and getting the hotfix. 

that is fantastic! Thank you!

hey, cisco doesn't know anything about this...

can you send me the hot fix if you got it? can you advise?

 

here is what cisco said:

I am Jashanjit Badwal from Cisco TAC and I’ll be assisting you with your case.

 

If I understand correctly, you have task notification health alerts stating that "Security Intelligence URL: memcap exceeded". From previous experience, unfortunately, this issue happens due to the total available memory in the appliance. What the alert means is that the appliance is not able to load all entries available in the memory and will only load partial SI entries. To overcome this issue, as you stated, we need to remove Security Intelligence categories by navigating to "Policies > Access Control > Edit the policy > Click on Security Intelligence tab" and remove the URL categories and DNS categories. The latter step frees up shared memory for SI to load more entries. At the time of this writing, there is no other documented workaround to apply besides the workaround already specified.

 

Best Regards,
Jashanjit Badwal

Sourcefire_3D_Defense_Center_S3_Hotfix_H-6.2.2.2-1.sh.REL.tar was the file I was given.

 

Not sure why they wouldn't be able to give it to you too.  I installed it into the FMC, redeployed policy, and all the memcap errors were fixed.

Can you send me that?


I put a copy of the file in my post.  Feel free to use it!

GOT IT! Thank you so much!

No problem! Hopefully it fixes the issues for you like it did for me!


I'll let you know shortly!

 

dang, it didn't fix it...

shoot...that was time consuming too...

I'll keep watching it and check it in the am

no go :(

That's strange it worked for us.  Our FMC is running 6.2.2.1 (build 73) and all our 5506X's are running Version 6.2.2 (Build 81).

 

Not sure why it didn't work for you. 

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card