13-12
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 13 Troubleshooting Connections and Resources
Monitoring Performance and System Resources
•
detailed
—Provides detailed trace results information in addition to the normal output.
•
xml
—Displays the trace results in XML format.
Example
The following example traces a TCP packet for the HTTP port from 10.100.10.10 to 10.100.11.11. The
result indicates that the packet will be dropped by the implicit deny access rule.
hostname(config)#
packet-tracer input outside tcp 10.100.10.10 80 10.100.11.11 80
Phase: 1
Type: ROUTE-LOOKUP
Subtype: Resolve Egress Interface
Result: ALLOW
Config:
Additional Information:
found next-hop 10.86.116.1 using egress ifc outside
Phase: 2
Type: ACCESS-LIST
Subtype:
Result: DROP
Config:
Implicit Rule
Additional Information:
Result:
input-interface: outside
input-status: up
input-line-status: up
output-interface: NP Identity Ifc
output-status: up
output-line-status: up
Action: drop
Drop-reason: (acl-drop) Flow is denied by configured rule
Monitoring Performance and System Resources
You can monitor a variety of system resources to identify performance or other potential problems.
•
show perfmon
Shows current and average statistics for NAT xlates, connections, inspections, URL access and
server requests, AAA, and TCP intercept.
•
show memory
Shows free and used memory.
•
show blocks
Shows memory block information based on block size.
•
show cpu
Shows CPU utilization.
•
show process
Shows system process information. Following are some useful variants:
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......