No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


The problem that Secospace product CPU-usage is too high

Publication Date:  2012-10-27 Views:  112 Downloads:  0

Issue Description

Check the product CPU-usage
HRP_M[USG]dis cpu-usage-for-user                                                                                              
===== Current CPU usage info =====                                                                                                
CPU Usage Stat. Cycle: 37 (Second)                                                                                                 
CPU Usage            : 98%                                                                                                         
CPU Usage Stat. Time : 2009-12-28  00:25:20                                                                                        
CPU Usage Stat. Tick : 0x77d(CPU Tick High) 0xf251d663(CPU Tick Low)                                                              
Actual Stat. Cycle   : 0x0(CPU Tick High) 0x44ef06d8(CPU Tick Low)

Alarm Information


Handling Process

Find attack source or replace the higher performance equipment to against attacks. If the attack source or destination is fixed, can through configuring packet filtering to block message or add to the destination black-hole routing.
1.To ensure the p2p effect, try to reduce the number of message detection, close the global p2p function, only can in specific inter-domain to limit.
2. If the address pool address is firewall interface IP, then close the packet filtering from the extranet to the NAT address pool;
3. If the address pool address is not interface address, need to configure the routing next hop as NULL 0 to address pool address.
4.Configure routing to NULL 0; Configure packet filtering forbid broadcast packet, and find broadcast packet source, reduce the sending packet number.
5.The live network flow is large and reaches the firewall performance, can replace the firewall having higher performance.
6.Open the acl acceleration, to check whether there is a decrease in the CPU.

Root Cause

details in the accessories