Cisco Systems IPS 7.1 Home Security System User Manual


  Open as PDF
of 1042
 
19-12
Cisco Intrusion Prevention System CLI Sensor Configuration Guide for IPS 7.1
OL-19892-01
Chapter 19 Configuring the ASA 5500-X IPS SSP
The ASA 5500-X IPS SSP and Memory Usage
For More Information
For detailed information about the Normalizer engine, see Normalizer Engine, page B-37.
The ASA 5500-X IPS SSP and Memory Usage
For the ASA 5500-X IPS SSP, the memory usage is 93%. The default health thresholds for the sensor
are 80% for yellow and 91% for red, so the sensor health will be shown as red on these platforms even
for normal operating conditions. You can tune the threshold percentage for memory usage so that it reads
more accurately for these platforms by configuring the memory-usage-policy option in the sensor health
metrics.
Note Make sure you have the memory-usage-policy option in the sensor health metrics enabled.
Table 19-1 lists the yellow-threshold and the red-threshold health values.
The ASA 5500-X IPS SSP and Jumbo Packets
The jumbo packet count in the show interface command output from the lines Total Jumbo Packets
Received
and Total Jumbo Packets Transmitted for ASA IPS modules may be larger than expected
due to some packets that were almost jumbo size on the wire being counted as jumbo size by the IPS.
This miscount is a result of header bytes added to the packet by the ASA before the packet is transmitted
to the IPS. For IPv4, 58 bytes of header data are added. For IPv6, 78 bytes of header data are added. The
ASA removes the added IPS header before the packet leaves the ASA.
Reloading, Shutting Down, Resetting, and Recovering the
ASA 5500-X IPS SSP
Note You can enter the sw-module commands from privileged EXEC mode or from global configuration
mode. You can enter the commands in single routed mode and single transparent mode. For adaptive
security appliances operating in multi-mode (routed or transparent multi-mode) you can only execute the
sw-module commands from the system context (not from administrator or user contexts).
Table 19-1 ASA 5500-X IPS SSP Memory Usage Values
Platform Yellow Red Memory Used
ASA 5512-X IPS SSP 85% 91% 28%
ASA 5515-X IPS SSP 88% 92% 14%
ASA 5525-X IPS SSP 88% 92% 14%
ASA 5545-X IPS SSP 93% 96% 13%
ASA 5555-X IPS SSP 95% 98% 17%