Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

firewall utilisation very high

Hi recentely i am facing problem in enterprice pix firewall.its goes up to 95

%.what is the average cpu utilisation and maximum utilisation for pix 525 series.


Re: firewall utilisation very high

A sudden increased of cpu utilization/processing can be anything, i.e PIX handling simultaneous/thousands of attack like DoS/DDoS, viruses, unreachable external syslog server and so on. Hard to pinpoint exact reason, but you need to check the PIX, i.e log entries for a clue, connection (who has highest no of connection and using which port, like 1 IP having hundreds of connected ports) and many more.

CPU utilization depends on how intensive of traffic inspection need to be performed by PIX. Basically, PIX handling bigger network with thousands on of clients probably has higher CPU utilization compared to smaller network with small no of traffic.

But at any time, it probably should not exceed 40% or even less.



Re: firewall utilisation very high

Take a look at this guide.

Monitoring PIX Performance:

General Troubleshooting Technotes:

hope that give a starting point.



New Member

Re: firewall utilisation very high

When you experience high CPU utilization on your PIX issue the following command to show the number of connections:

show conn count

If the "in used" connections is both high and near the same level as "most used" then you're probably under denial-of-service attack such as TCP SYN half-open.