Solved

URGENT: high severity problem with the PIX 525 at Osaka conference

Posted on 2008-10-20
8
1,935 Views
Last Modified: 2011-10-19
Dear all,

Bellow you will find the description my colleagues sent. A memory increasing problem risk to provoke a general outage at the plenary (Client coference we run) that is running in Japan today.
 

-      SEVERITY HIGH : PIX FW version 8.0.4 memory increasing problem
The upgrade of the IOS on the PIX from 6.3 to 8.0.4 has fixed the problem on the VPN Client which used IPSEC. However, this has introduced a new problem. The memory usage on the PIX is continuously increasing until the max. When it reaches the limit of the capacity, there are no Internet Access here.

It has happened around 10:00 this morning. We have decided to failover the Standby unit.
But, The standby unit has a copy of the memory content thus we were in the same situation.
Finally, We have shut down the Standby unit and start the Primary one.
After the start-up we had only 84MB used now it is increasing by 25MB every hours.
We suspect 2 processes on the PIX:
Dispatch Unit and Unicorn Admin Handler are 2 processes that used the biggest amount of memory and they are increasing.

Thanks in advance for anything you can do to help us to resolve this critical issue.

If you need more information, you can reach me at :

miguel.paton@etsi.org


Best regards

PIX-125MB-AFTER-2H.TXT
PIX-171MB-AFTER-6H.TXT
0
Comment
Question by:martineit
8 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 22756907
From Cisco web site
Here are some possible causes and resolutions for high memory utilization. It sounds like a memory leak and may have to contact Cisco TAC for an upgrade to the OS, or downgrade to 8.0(3)19 or something..

Event logging: Event logging can consume large amounts of memory. In order to resolve this issue, install and log all events to an external server, such as a syslog server.

Memory Leakage: A known issue in the security appliance software can lead to high memory consumption. In order to resolve this issue, upgrade the security appliance software.

Debugging Enabled: Debugging can consume large amounts of memory. In order to resolve this issue, disable debugging with the undebug all command.

0
 
LVL 1

Author Comment

by:martineit
ID: 22756987
Hello,

Seams to me the origin of the memory leak is on a bug quite well known : CSCsj84640 : Memory leak on CRYPTO_malloc.

There is no available higher version than  8.0.4. The version bellow which doesn't have this bug is the the Version 7.1(2).
Before instruct my colleagues to downgrade to the this version I'd like to know if there is any other solution. The PIX is in production at this moment.

Best regards

0
 
LVL 4

Expert Comment

by:yurisk
ID: 22757651
Hard to believe someone has other options here - problem started clearly after upgrade, the 1st
solution that TAC would ask to try - upgrade/downgrade , the only question asked here is to what version.
I 've had one client with VPn clients problem - more than 5 connections were freezing the ASA 5510  on memory( it was FOS 7.0)  , after a search on cisco.com I found 7.2(4) to be least buggy , without using 8.x that would for sure introduce new bugs.So  It has already passed about 2 months - havent heard from this client yet.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 79

Expert Comment

by:lrmoore
ID: 22759199
Open a TAC case with Cisco. They may have an unreleased bug fix for you.
0
 

Expert Comment

by:Rick
ID: 23680135
any progress on this subject/post?

i've wrote the other post you referenced to...

These last days we are having increased fallouts, i'm runnung os 8.0.(4) and adsm 6.1.(5)51 on our Pix 515E / 64MB. we have 1 site2site vpn and use the device for remote access for 5 / 10 employees..
Mostly it begins with the pix not being to able to accept incomming VPN connects and since yesterday it block all incomming connections for remote control when the memory is full. So i have to do hardware reboot. Earlier i rebooted the machine remotely by cli.
Since the PIX support is dead in june, should i even buy a ASA?? it uses the same software and probebly has the same errors...
Regards, Rick
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 23680284
>should i even buy a ASA??
Absolutely, without question. It does not use the same hardware and the software is not exactly the same. Better memory management on ASA. More development is going into the ASA because the PIX is dead.
You can also try upgrade to a bug fix release 8.0(4)16 or 8.0(4)23
 
0
 

Expert Comment

by:Rick
ID: 23680521

haha, this is funny :-S
I've listed 4 OS versions, check out the bugs.. listed in each (and solved or not...)
taken from cisco release notes for the asa 5500 series

ASA 5500 series version 8.0.(3)
CSCsj84640 - Memory leak on CRYPTO_malloc (Open Caveats)
CSCso64944 - (doesn't excist)
CSCsj25896 - (doesn't excist)

ASA  5500 series version 8.0.(4)
CSCsj84640 - (doesn't excist? / not solved or open!)
CSCso64944 - ASA memory leak due to IPSEC (Open Caveats) (huh?? new name?)
CSCsj25896 - ASA may reload with traceback in Thread name: CTM Message Handler (Resolved Caveats)

(i don't know if i would apply a 5580 to a 5500 series, but ok.. just to show u)
ASA  5580 version 8.1.(1)
non of the above ceveats! (not open or closed)

ASA  5580 version 8.1.(2)
CSCsj25896 Crypto Accelerator Memory Leak (re-opened under a new name??)

Very strange all!
A company who does some IT projects for us suggested that we buy a Zyxcel firewall/router, 1/3 cost of a new 5510
0
 

Accepted Solution

by:
Rick earned 500 total points
ID: 23681130
Taken from the Cisco Bug toolkit. I suggest to close this issue

"This status of this bug (CSCsj84640 ) is terminated,

suggesting that a conscious decision to not fix this bug was made.
It is possible the engineers were not able to duplicate the issue in a lab environment or some other reason was made to terminate this bug.

This bug has a Severe severity level 2 designation. Important functions are unusable but the router's other functions and the rest of the network is operating normally."

Probely going for a 5505 or 5510 soon, gonna try 8.0(4)23 later on, hope it helps!
Thnx
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Cisco Pix/ASA hairpinning The term, hairpinning, comes from the fact that the traffic comes from one source into a router or similar device, makes a U-turn, and goes back the same way it came. Visualize this and you will see something that looks …
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question