Hi all, we're replacing EOL 15000 series FWs with 6000 series. The configurations are largely identical (using ClusterXL in active/standby) and the replacement FWs are sized correctly. We've had several failed migration attempts to the new Firewalls - all acceptance tests complete succesfully, yet when production traffic starts to return to normal levels following end of the outage window, poor performance is observed.
According to CPVIEW, there are a high number of drops due to "Capacity" - yet nowhere can I find what this relates to. It can't be CPU or interface, since these are nowhere near maximum. Does anyone know what can cause drops due to "capacity"? This counter can be seen to incremement at a high rate and having ruled everything else out, it would appear this is the cause of the perceived performance issues.