Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » [H/W] Cisco pfSense Replacement?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[HELP] Help with a Cisco 2620. »
« [HELP] SDM Initializes but won't function  
AuthorAll Replies


sporkme
drop the crantini and move it, sister
Premium,MVM
join:2000-07-01
Netcong, NJ

reply to MattE
Re: [H/W] Cisco pfSense Replacement?

said by MattE See Profile :

Nowhere near the 10000 limit. I've never seen it higher than 800 states, with 2-4% CPU usage and like 4% memory.
Something is amiss then if every client login causes 300 outbound connections and you don't peak over 800 states. Just a handful of logins should bring you near the 10K default max - the state entries linger a bit.

It certainly wouldn't hurt to bump that up to 50K or so to see what happens while you wait on the new hardware.


MattE
Obama '08
Premium
join:2003-07-20
Jamestown, NC
·North State Commun..
·Corporate Colocation

said by sporkme See Profile :

said by MattE See Profile :

Nowhere near the 10000 limit. I've never seen it higher than 800 states, with 2-4% CPU usage and like 4% memory.
Something is amiss then if every client login causes 300 outbound connections and you don't peak over 800 states. Just a handful of logins should bring you near the 10K default max - the state entries linger a bit.

It certainly wouldn't hurt to bump that up to 50K or so to see what happens while you wait on the new hardware.
It actually happened again today. I'm talking with our developer now and it appears there is "retry logic" in the code that retries in a 5 batch loop, INDEFINITELY, if there is any sort of error. I think that is triggering the outbound issue.

I was on the FW when it happened today and the states were hovering around 450, then the firewall log went crazy blocking connections outbound to the same individual destination IP from 2 of our servers.
Forums » Equipment Support » Hardware By Brand » Cisco[HELP] Help with a Cisco 2620. »
« [HELP] SDM Initializes but won't function  


Friday, 05-Sep 23:50:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [178] Google Browser Available Today
· [123] The Best Bandwidth Meters For Comcast Customers
· [111] Comcast Pays Florida $150K For Misleading Consumers
· [98] Labor Day Open Thread
· [88] Verizon, AT&T Offer New DSL Promotions
· [73] Oh Look, Another Ridiculously Huge Wireless Data Bill
· [66] Google Chrome Runs The Internet Gauntlet
· [65] Routing Around The United States
· [56] iPhone Users Greeted With Morning Outage
· [51] Deconstructing The Exaflood Myth
Most people now reading
· Is my landlord trying to screw me? [Home Repair & Improvement]
· House Inspection Woes [Home Repair & Improvement]
· Oil Heat vs Electric? [Home Repair & Improvement]
· [new forum] Gay / Lesbian Talk [Forum Feature Requests]
· [iPhone] Apps not working?? [All things Macintosh]
· Where do the experts buy their splitters? Cable? [Comcast HSI]
· 1080P [Verizon FIOS TV]
· Worried ABOUT TEKSAVVY'S future! [TekSavvy]