The appearance cpu acceptance Command

The appearance cpu acceptance Command

The appearance cpu acceptance command provides a snapshot of the concise CPU utilization

statistics. Although this advice is not advantageous for history or trending purposes,

it can anon acquaint you if the CPU is active at the time the

command is executed.This command does acquiesce you to analysis in absolute time if the

CPU is the account of any achievement degradations. For example:

PIX1# appearance cpu usage

CPU appliance for 5 abnormal = 2%; 1 minute: 1%; 5 minutes: 1%

If you doubtable that IPsec encryption is causing achievement degradation,

use this command afore axis on encryption to booty a baseline of CPU

www.syngress.com

606 Chapter 10 • Troubleshooting and Achievement Monitoring

utilization.Then accredit IPsec and run the command again. Compare the CPU

utilization. Run the command a few times over a time breach to ensure that the

data you aggregate is accurate.

CPU Performance Monitoring

CPU Performance Monitoring

Your CPU does it all: passes traffic, creates VPN tunnels, and performs encryption

on demand.The aphorism of deride is that during accustomed operational mode, the CPU

load should break beneath 30 percent, on average. During aiguille cartage hours and

attacks, you will see the CPU billow up higher, but that is normal. However, if the

CPU appliance consistently stays aloft 30 percent with accustomed arrangement activity,

consider advance to a added able model.

Many functions can tax CPU, but encryption (DES and 3DES) has the

biggest abeyant to absorb your CPU’s adored time. If you are activity to

deploy a ample cardinal of encrypted tunnels (VPNs), we acclaim you monitor

the processor carefully. If appliance goes high, accede abacus a agenda to the

PIX to handle VPN functions (the VPN Accelerator Card). Alternatively, you can

think about offloading VPN functions from the PIX to a committed VPN concentrator

(such as the VPN 3000 alternation from Cisco).The bulk of cartage passing

through the firewall is additionally a factor. If you are seeing aerial cartage utilization, monitor

the CPU appliance on a approved base to ensure that it is not peaking.The

best way to do this is to use a apparatus such as MRTG or HP OpenView to monitor

the CPU through SNMP. See Chapter 6 for capacity on how to do this.

Logging and the boundless use of alter commands additionally affect CPU utilization.

To abstain arresting adored CPU cycles, you should set logging to the minimum

level of advice that you absolutely need.Table 10.4 displays the logging

levels you accept at your disposal. If there is a acumen you charge aerial logging levels,

consider axis off log letters that you do not charge application the no logging message.

See Chapter 6 for abundant advice on logging.

www.syngress.com

Troubleshooting and Performance Monitoring • Chapter 10 605

Table 10.4 Logging Levels

Description Numerical Value

Emergency 0

Alert 1

Critical 2

Error 3

Warning 4

Notification 5

Informational 6

Debugging 7

You can actuate the logging options and levels that are enabled on a PIX

firewall application the appearance logging command. For example, on this firewall, all logging

is disabled:

PIX1# appearance logging

Syslog logging: disabled

Facility: 20

Timestamp logging: disabled

Standby logging: disabled

Console logging: disabled

Monitor logging: disabled

Buffer logging: disabled

Trap logging: disabled

History logging: disabled

Monitoring and Troubleshooting Performance

Monitoring and Troubleshooting

Performance

We mentioned ahead the accent of analogous the archetypal of PIX firewall

you arrange to the demands you abode on it.You charge to accede several factors

in accession to the bulk of cartage you are passing.Table 10.3 summarizes the

loads that anniversary archetypal can handle, including advice about encryption.

Ensure that your architecture considers these amount limits.

www.syngress.com

your reseller adeptness not accept the abyss and across of

knowledge that Cisco does, as a reseller, it adeptness be able to

offer you a abundant abatement on support.

 Using Cisco via the SMARTnet affairs can ensure that you

always accept admission to a ample basin of able adeptness and

the “latest and greatest” advice apropos configuration,

troubleshooting, and bug fixes. The Cisco Web site

offers a abundance of accoutrement and advice that you can use to

aid your troubleshooting. You can additionally opt to admission the

Cisco Connection Online (CCO) associates to accretion admission to

even added abutment such as the adeptness to accessible or browse TAC

cases online. SMARTnet additionally provides accouterments replacement

and software upgrades.

Two things can breach on your PIX firewall: the software or the hardware.

To assure adjoin accouterments failures, you accept the advantage of stockpiling

spares. Depending on the arrangement of alive to banal units, this choice

could be amount prohibitive. Software can be bedeviled with bugs that you

discover afterwards you accept deployed the absolute configuration. Certain commands

or appearance adeptness not assignment as you appetite them to or not assignment at

all. In any case, you will crave advice from Cisco to assignment around

the botheration or admission to the latest absolution of software that fixes your

problem. In general, you are bigger off putting your firewall beneath a

SMARTnet aliment arrangement with Cisco to ensure that you always

have admission to the latest releases of software. Software is generally

much added difficult to fix on your own than hardware, which you can

easily alter in case of a failure. You absolutely cannot carbon the software

code to fix a problem, and you’ll end up spending an excessive

amount of time developing a workaround to a botheration acquired by a

buggy software release.

Troubleshooting and Achievement Ecology • Chapter 10 603

Table 10.3 PIX Firewall Archetypal Appearance and Capabilities

Model Accouterments Cleartext DES IPsec 3DES IPsec Simul-

Maximums Through- Through- Through- taneous

(CPU/SDRAM put put put VPN

/FLASH) Tunnels

501 133MHz AMD 10Mbps 6Mbps 3Mbps 5 peers

SC520

16MB RAM

8MB Flash

506 200MHz Intel 20Mbps 20Mbps 10Mbps 25 peers

(EOS) Pentium

32MB RAM

8MB Flash

506E 300MHz Intel 20Mbps 20Mbps 16Mbps 25 peers

Celeron

32MB RAM

8MB

515 200MHz Intel 146Mbps 20Mbps 10Mbps 25 peers

(EOS) Pentium

32MB RAM

8MB Flash

515E 433MHz Intel 188Mbps 33– 63Mbps UR 2,000

Celeron 120Mbps 22Mbps R

64MB RAM

16MB Flash

520 350MHz Intel 370Mbps 20Mbps 10Mbps *

(EOS) Celeron

64MB RAM

16MB Flash

525 600MHz Intel 360Mbps 120– 70Mbps 2,000

Pentium III 140Mbps

256MB RAM

16MB Flash

535 1GHz Intel 1Gbps 200Mbps 100Mbps 2,000

Pentium III

1GB PC133 RAM

16MB Flash

www.syngress.com

604 Chapter 10 • Troubleshooting and Achievement Monitoring

Cleartext throughput agency unencrypted abstracts casual through the firewall,

while IPsec (DES and 3DES) throughput is advised encrypted.The cleartext

throughput of the PIX firewall ranges from a low of 10Mbps to a aerial of 1Gbps.

Three key apparatus of the PIX firewall that affect achievement are the

CPU, memory, and arrangement interfaces.You charge to accept how to monitor

these apparatus and ensure that their amount is not extensive the limits.We discuss

the ecology of these three apparatus in the afterward sections.The ultimate

question is, can your firewall handle the endless you will abode on it?

Support Options as Troubleshooting Tools

Support Options as Troubleshooting Tools 631

The PIX firewall can be a actual analytical accessory on your network. Network

architecture planning needs to accede assorted abutment options to

handle the accident or abortion of your PIX firewall. Accede this troubleshooting

by prevention, if you will. You can do it all yourself, acreage out

support to a third-party bell-ringer (reseller), or acquirement abutment from

Cisco. Let’s appraise anniversary option:

 In the “do it yourself” approach, you artlessly acquirement the

software and hardware, with no assurance or abutment other

than what was provided as standard. If annihilation goes wrong,

you charge the adeptness and assets to fix it yourself.

 In the third-party option, you accept a appropriate arrangement

with your bell-ringer (reseller) to accommodate whatever you charge to

fix your problem, whether software or hardware. Although

your reseller adeptness not accept the abyss and across of

knowledge that Cisco does, as a reseller, it adeptness be able to

offer you a abundant abatement on support.

 Using Cisco via the SMARTnet affairs can ensure that you

always accept admission to a ample basin of able adeptness and

the “latest and greatest” advice apropos configuration,

troubleshooting, and bug fixes. The Cisco Web site

offers a abundance of accoutrement and advice that you can use to

aid your troubleshooting. You can additionally opt to admission the

Cisco Connection Online (CCO) associates to accretion admission to

even added abutment such as the adeptness to accessible or browse TAC

cases online. SMARTnet additionally provides accouterments replacement

and software upgrades.

Two things can breach on your PIX firewall: the software or the hardware.

To assure adjoin accouterments failures, you accept the advantage of stockpiling

spares. Depending on the arrangement of alive to banal units, this choice

could be amount prohibitive. Software can be bedeviled with bugs that you

discover afterwards you accept deployed the absolute configuration. Certain commands

or appearance adeptness not assignment as you appetite them to or not assignment at

all. In any case, you will crave advice from Cisco to assignment around

the botheration or admission to the latest absolution of software that fixes your

problem. In general, you are bigger off putting your firewall beneath a

SMARTnet aliment arrangement with Cisco to ensure that you always

have admission to the latest releases of software. Software is generally

much added difficult to fix on your own than hardware, which you can

easily alter in case of a failure. You absolutely cannot carbon the software

code to fix a problem, and you’ll end up spending an excessive

amount of time developing a workaround to a botheration acquired by a

buggy software release.

Downloading Captured Traffic

Downloading Captured Traffic

The PIX firewall saves packet abduction buffers in PCAP format, which can be

downloaded and beheld with third-party software such as Ethereal or tcpdump.

The abduction can be downloaded either application HTTPS or TFTP.To download the

file application HTTPS, access the adapted URL to the PIX firewall.The syntax is

as follows:

https://pix_ip_address/capture//pcap

www.syngress.com

Figure 10.24 Continued

Troubleshooting and Performance Monitoring • Chapter 10 601

For example:

https://192.168.1.1/capture/inside/pcap

This syntax downloads the packet abduction to your applicant in PCAP format.

Alternatively, you can download the book application TFTP.This is able using

the archetype command on the PIX firewall.The syntax is as follows:

copy capture: tftp:/// [pcap]

Without the pcap keyword, the ASCII packet headers will be copied.With the

pcap keyword, the bifold book in PCAP architecture will be copied. For example:

PIX1# archetype capture:inside-traffic tftp://192.168.99.99/pix-capture pcap

copying Abduction to tftp://192.168.99.99/pix-capture:

In our example, we are artful the inside-traffic abduction (in PCAP format) to

the TFTP server at 192.168.99.99 to the pix-capture filename. Once the book has

been copied, you can use any of the above software bales to open

and assay the captured packets.