Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

FWSM with contexts - Broadcast storm impact CPU

Hi,

we have a FWSM (4.1(5)) configured with several contexts.

Last day we had a broadcast storm in one VLAN connected to one FWSM context and all contexts were impacted with loss of service.

We could check that CPU in impacted context went to 50 - 60 % but in fact service allocated in other contexts were impacted.

We have Resource Class implemented, but there is nothing about CPU usage (only connections, xlates, .... ).

Any idea about how to protect contexts against a broadcast storm or high CPU usage in one context ?

Thanks a lot

Felipe

  • Firewalling
Everyone's tags (3)
1 REPLY
Cisco Employee

FWSM with contexts - Broadcast storm impact CPU

Hi Felipe,

Unfortunately, the FWSM's CPU is not virtualized across contexts like the conn tables, xlate tables, etc are. High CPU caused by traffic in one context will indeed affect traffic on other contexts on the same physical firewall, which is a limitation of the architecture.

-Mike

484
Views
0
Helpful
1
Replies