cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
418
Views
0
Helpful
3
Replies

Problem with my 2522 router

utawakevou
Level 4
Level 4

I have a problem today. I couldnt connect(telnet) to my router ethernet port. When I log into the console port I got this messages:

-Process= "TTY Background", ipl= 0, pid= 22

-Traceback= 314EA88 314F7B8 31650E8 316035A 30E4248 30E464C 30E4130 30E597C

%SYS-2-CFORKMEM: process create of Exec failed (no memory)

-Process= "TTY Background", ipl= 0, pid= 22

-Traceback= 3165136 316035A 30E4248 30E464C 30E4130 30E597C

%% Unable to create EXEC - no memory or too many processes

%% Unable to create EXEC - no memory or too many processes

%% Unable to create EXEC - no memory or too many processes

%% Unable to create EXEC - no memory or too many processes

%SYS-2-MALLOCFAIL: Memory allocation of 4000 bytes failed from 0x31650E0, pool 0

-Process= "TTY Background", ipl= 0, pid= 22

-Traceback= 314EA88 314F7B8 31650E8 316035A 30E4248 30E464C 30E4130 30E597C

%SYS-2-CFORKMEM: process create of Exec failed (no memory)

-Process= "TTY Background", ipl= 0, pid= 22

-Traceback= 3165136 316035A 30E4248 30E464C 30E4130 30E597C

%% Unable to create EXEC - no memory or too many processes

%SYS-3-CPUHOG: Task ran for 4156 msec (114/7), Process = ARP Input, PC = 317EC92

-Traceback= 31597F2 317EC9A

Could this be the IP v4 problem or could it be the worm blaster problem. We did a scan on all the subnet address connected to us via this router and found out that some of the machines are not patched.

As for the IP v4 problem, I have downloaded the IOS patch and already load it. Here is the IOS image I download and currently using:c2500-i-l.112-15b

My CPU process is going up to 98%:

------------------ show process cpu ------------------

CPU utilization for five seconds: 98%/19%; one minute: 79%; five minutes: 62%

PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process

1 128 211 606 0.00% 0.00% 0.00% 0 Load Meter

2 15488 2169 7140 0.00% 0.90% 1.71% 0 Exec

3 31572 328 96256 9.65% 4.96% 3.53% 0 Check heaps

4 144 32 4500 0.00% 0.00% 0.00% 0 Pool Manager

5 0 2 0 0.00% 0.00% 0.00% 0 Timers

6 4928 975 5054 0.16% 0.49% 0.60% 0 ARP Input

7 0 1 0 0.00% 0.00% 0.00% 0 SERIAL A'detect

8 20 39 512 0.00% 0.00% 0.00% 0 SYNCCD2430 Helper

9 191024 20857 9158 9.90% 10.56% 10.38% 0 IP Input

10 884 422 2094 0.08% 0.07% 0.06% 0 CDP Protocol

11 0 1 0 0.00% 0.00% 0.00% 0 Asy FS Helper

12 548 630 869 0.08% 0.06% 0.03% 0 TCP Timer

13 24 5 4800 0.00% 0.00% 0.00% 0 TCP Protocols

14 0 1 0 0.00% 0.00% 0.00% 0 Probe Input

15 0 1 0 0.00% 0.00% 0.00% 0 RARP Input

16 372 144 2583 0.00% 0.01% 0.00% 0 BOOTP Server

17 1360 1440 944 0.40% 0.49% 0.49% 0 IP Background

18 131336 577 227618 0.00% 14.32% 13.88% 0 IP Cache Ager

19 0 1 0 0.00% 0.00% 0.00% 0 Critical Bkgnd

20 80 22 3636 0.00% 0.00% 0.00% 0 Net Background

21 12 9 1333 0.00% 0.00% 0.00% 0 Logger

22 1796 1004 1788 0.08% 0.11% 0.10% 0 TTY Background

23 520 1017 511 0.08% 0.03% 0.00% 0 Per-Second Jobs

24 10028 1016 9870 1.06% 0.81% 0.76% 0 Net Periodic

25 376 369 1018 0.00% 0.00% 0.00% 0 Net Input

26 916 212 4320 0.08% 0.08% 0.08% 0 Compute load avgs

27 1124 18 62444 0.00% 0.06% 0.05% 0 Per-minute Jobs

28 33620 12469 2696 1.39% 1.55% 1.47% 0 HyBridge Input

29 8 2 4000 0.00% 0.00% 0.00% 0 CCP manager

30 432 385 1122 0.00% 0.00% 0.00% 0 PPP manager

31 308 1023 301 0.00% 0.00% 0.00% 0 Multilink PPP

32 0 2 0 0.00% 0.00% 0.00% 0 Multilink PPP out

33 4 2 2000 0.00% 0.00% 0.00% 0 Multilink event

34 184 92 2000 0.00% 0.02% 0.00% 0 IP SNMP

35 0 1 0 0.00% 0.00% 0.00% 0 SNMP Traps

36 8072 2506 3221 0.57% 0.51% 0.46% 0 Spanning Tree

37 8 2 4000 0.00% 0.00% 0.00% 0 Tbridge Monitor

38 72 55 1309 0.00% 0.01% 0.00% 0 IP-RT Background

39 3756 164 22902 0.00% 0.58% 0.69% 11 Virtual Exec

40 11720 1175 9974 55.88% 23.42% 7.68% 12 Virtual

Please advice.

3 Replies 3

osam
Level 1
Level 1

Well, to check whether or not it is a security problem related to Blaster worm, first disconnect all ports connected to the router and run it and see what happens, if you don't get this error for about 5 minutes, then make sure you have port 135, 137,138 and 139 blocked in the router in all directions (apply same access list inbound on all interfaces, and make sure to log violations).. connect it back to the network and monitor the violations in your access-list.

If you have high hits in port 135, then, this is a blaster virus kind of a problem.

Just curious, how many flash and DRAM do you have in this router? How many serial interface you have connected and forwarding IP traffic? And what version do you have?

You may need to check which process eating up your memory "show proces mem". In the "show process cpu" you have listed, I can see a huge IP packets process.

If blocking 135 doesn't help.. try this in the ocnfiguration mode,

scheduler interval 500

This will prevent the router to get locked in one process..

The 2522 route I got have 8 Mbps of Flash memory and 16Mbps of DRAM. I check it out and found out that 50% of memory is used up.

I manage to block the port used by worm blaster to exploit other system using ACL posted during the Cisco Security Notice on W32.Blaster Worm. This fix it. Thanks anyway. This is quite a learning expereince for me :)

Regards

No problem..

If you are using more than I would say 4 serial ports (specially those low speed ones), you will sure need to upgrade your DRAM.. Low speed interfaces consume more memory in high traffic because of the more buffering and processor threads needed to be created.