High CPU Usage (Capwap?)

Options
Skylink
Skylink Posts: 32  Freshman Member
First Anniversary 10 Comments Friend Collector
edited April 2021 in Security
Hi!
maybe I have a problem with our firewall (USG60W).

For about 10 days the use of the CPU has become abnormal (24 hours a day)
I have attached an image with the normal situation, of the day on which the anomaly occurred (Sunday, with the company closed) and the current situation.

By running the "debug system ps" command I only notice a high CPU usage by the "capwap_srv" service but I have no elements to see if it was also like this previously.

I have not yet restarted the firewall and the firmware in use is not the last one (I use 4.33)
how should I proceed for further analysis and understand if it is an unjustified use of the cpu?


Comments

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,450  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    There are some improvements regarding to CAPWAP since V4.33, you can upgrade the device firmware to the current release (4.38) and see if this version can solve the High CPU symptom.
    BTW, is the CPU usage always on high side or it will reduce sometimes?
  • Skylink
    Skylink Posts: 32  Freshman Member
    First Anniversary 10 Comments Friend Collector
    Options
    Hi,
    the usage was always very high.

    I just upgrade the firmware to 4.38 version and now the CPU usage (and Capwap) are "normal" again.

    I'll check again tomorrow morning when the company is full of clients and the VPN is used.

    But 2 questions more...
    1. loading the new firmware, after 25 minutes I had to turn the firewall off and on again to restart it. He seemed stuck ("sys" led was blinking).
    From interfaces the upgrade process seems to have gone well.
    2. the USG60W is detected as "SHARE60" model .. is that right?



    update..

    after reload the firmware using Cloud and not a local file...

    the model is right and the firewall start without problem after 6 minutes.
  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,450  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @Skylink,

    The firmware update time depends on how complex the configuration file is.

    In case of any risk during firmware upgrade, you can connect serial console to check firmware update status.

    As for model name "SHARE60", that’s expected behavior. It will auto recovery after device reboot.

    The following information for your reference

    https://businessforum.zyxel.com/discussion/3299/why-does-the-firmware-version-show-as-4-35-vvvv-0-4-35-wwww-0-4-35-zzzz-0-4-35-yyyy-0/p1


  • Skylink
    Skylink Posts: 32  Freshman Member
    First Anniversary 10 Comments Friend Collector
    Options
    I don't know if the firmware uograde o simply a reboot has worked but.. now it "works better".


Security Highlight