Hello everyone,
Due to the current situation, we all know lots of users are working remotely.
I am having a weird problem on my R80.30 cluster (5400 appliances) :
The CPU is dangerously increasing during daytime (it reached 100% today). I noticed via cpview that most of the CPU is consumed by a few connections :
These connections are always using TCP/7080 port and are displayed as "TCP:empowerid".
This is always from a 172.16.50.x host (which is our remote access VPN users pool) to 10.75.30.248 which is one of our Cisco Jabber server. Users and IP can be different, it seems to be happening randomly in the remote access VPN pool.
I managed to lower the CPU by manually disconnecting the involved users as you can see on the following graph at 14h and 16h (CPU is in yellow) :
Then as soon as someone is starting to work in the working, CPU is increasing like crazy... and eventually reaches 100%.
Same problem, same workaround for now, and here is the last graph I have :
I added a rule to drop the TCP/7080 service for now it's working properly, but we may need to accept this service later in order to make Jaber calls work when working remotely (it doesn't work for now and I've no clue why but its another topic).
Here's my GW's version :
Does someone has already seen this before? 😞
Thanks for your help!
piou_piou