As shown above, accessing internet through USG2100 is slow.
1. cpu-usage of USG2100 is 99%
2. There are warning messages in logbuffer as below:
%Mar 22 10:36:23 2013 USG2120BSR SEC/4/ATCKDF:AttackType:Udp flood attack; Receive Interface: Ethernet0/0/0 ; proto:UDP ; from 188.8.131.52:33634 184.108.40.206:52701 220.127.116.11:44838 18.104.22.168:54497 22.214.171.124:61329 126.96.36.199:2527 188.8.131.52:14622 184.108.40.206:40696 220.127.116.11:26268 18.104.22.168:44076 22.214.171.124:25043 126.96.36.199:40963 ; to 188.8.131.52:53 ; begin time :2013/03/22 10:35:55; end time: 2013/03/22 10:36:20; total packets: 199; max speed: 1014(packet/s);
1. Check the bandwidth and sessions on USG2100, and they are in normal range.
2. There are UDP attacks to 184.108.40.206, checking route to this ip address and found the nexthop is uplink device
<USG2120BSR>display fib 220.127.116.11
Route Entry Count: 1
Destination/Mask Nexthop Flag TimeStamp Interface TunnelID
0.0.0.0/0 18.104.22.168 GSU t Eth0/0/0 -
3. Checking the configuration on USG2100, found 22.214.171.124 which belongs vlanif 5 should connect to interface Ethernet1/0/4 whose current state is down.
ip address 126.96.36.199 255.255.255.248
port access vlan 5
Ethernet1/0/4 current state : DOWN
Line protocol current state : DOWN
4. The route on uplink device to 188.8.131.52 is USG2100, but USG2100 forwards the packets back to uplink router via default route because the interface which connect 184.108.40.206 is down. So, there is a route loop between USG2100 and uplink device.
5. This problem is resolved by configuring black hole route to 220.127.116.11 on USG2100
CPU usage too high usually caused by performance insufficient:
1. bandwidth/sessions/acl rules overload
2. route loop
4. ip duplicate
CPU usage abnormal usually caused by bandwidth/sessions/acl rules overload, route loop, attack, ip address duplicate and so on. When troubleshooting, please check them one by one.