- CheckMates
- :
- Products
- :
- General Topics
- :
- High CPU load on wsman TCP/5985 traffic
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
High CPU load on wsman TCP/5985 traffic
Once a month there is a strange behavior of CPU load.
We have configured to send events from sources to the WEC event collector on port 5985.
Usually the CPU load is normal.
But on a certain day through cpview we see that all the load is due to wsman traffic on port 5985. CPU load is 90-100% and firewall becomes even unavailable.
We tried to allow all traffic from our subnet to the WEC using fast accel, but it doesn't work.
The problem is solved only by blocking this traffic. Then we gradually allow traffic up to the WEC so that the event queue goes up to it. We allow only part of the subnet to pass traffic, then when the load is reduced we allow the next part of the subnet and so on until all subnets are in the allowed rules again.
Can you tell me what the problem might be? Can it be related to CheckPoint?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sounds like you are dealing with an occasional elephant flow (or flows) on this port. What does fw ctl multik print_heavy_conn show if run within 24 hours of one of these events? What is your code and HFA level?
If the fast_accel did not improve the situation it almost certainly means that traffic is F2F/slowpath which is immune to fast_accel definitions. You'll have to determine why that traffic is F2F before you can improve the situation. Once you provide your code level I'll provide further steps.
CET (Europe) Timezone Course Scheduled for July 1-2
