Hi Guys,
i'm not sure if this is normal or not. but as of today we are troubleshooting one of our customer firewall and we notice that UDP DNS is taking up most of the CPU processing and from almost 200K+- concurrent connections 180K+ is being used by UDP. Looking for some comment and suggestion from all the masters. We are currently doing some checking on what is causing the memory to utilize almost 70%. the appliance is using 6700 with 32GB of RAM installed inside the appliance.
Free -h
total used free shared buff/cache available
Mem: 31G 10G 5.3G 10G 15G 8.4G
Swap: 31G 3.0M 31G
fw ctl pstat
Virtual System Capacity Summary:
Physical memory used: 73% (19813 MB out of 27113 MB) - below watermark
Kernel memory used: 9% (2501 MB out of 27113 MB) - below watermark
Virtual memory used: 63% (17217 MB out of 27113 MB) - below watermark
Used: 17217 MB by FW, 36414 MB by zeco
Concurrent Connections: 197791 (Unlimited)
Aggressive Aging is enabled, not active
Kernel memory (kmem) statistics:
Total memory bytes used: 4064425705 peak: 17248058149
Allocations: 2378340323 alloc, 0 failed alloc
2235864245 free, 0 failed free
Cookies:
3511454616 total, 89080 alloc, 89080 free,
2167360 dup, 2206143026 get, 1969436521 put,
1807612677 len, 95659764 cached len, 23567 chain alloc,
23567 chain free
Connections:
981379508 total, 11899190 TCP, 964579454 UDP, 4900744 ICMP,
120 other, 456 anticipated, 24810 recovered, 197797 concurrent,
2034871 peak concurrent
Fragments:
560707 fragments, 276569 packets, 12 expired, 0 short,
0 large, 0 duplicates, 0 failures
NAT:
305076803/0 forw, 309191099/0 bckw, 1318730867 tcpudp,
4044131 icmp, 552888828-967582277 alloc
Sync: Run "cphaprob syncstat" for cluster sync statistics.
currently only below blades are enabled.
Firewall, IPSec VPN, Mobile Access.
Firewall version is R81.20 with HFA 26
Any suggestion