Just upgraded a 4430 from 17-07-02 to the R11-6-0. The CPU whenever I check using SSH is really high usage by PC Config, at times 80%+. The config is set to "no http" and "no http secure-server". Not causing issues (yet). This is our main router, we are an ISP. It has no firewall enabled, it is just a router
Here is a snap shot
ADTRAN, Inc. OS version R11.6.0.SA
Mainline Version: ENM.15.45
P4 Changelist: 198400
Checksum: BF5453EE
Built on: Thu Apr 16 14:30:39 2015
Upgrade key: df83aec2cd602718a1852dd29c65770b
Boot ROM version 17.04.01.00
Checksum: 70EF
Built on: Wed Dec 10 09:35:38 2008
Compatibility Version: 0
Copyright (c) 1999-2015, ADTRAN, Inc.
Platform: NetVanta 4430, part number 1700630E1
Serial number LBADTN1012AJ966
Flash: 33554432 bytes DRAM: 268435455 bytes
uptime is 0 days, 3 hours, 19 minutes, 19 seconds
System returned to ROM by Soft Reset
Current system image file is "NV4430A-R11-6-0-SA.biz"
Primary boot system image file is "NV4430A-R11-6-0-SA.biz"
Backup boot system image file is "NV4430A-17-07-02-00.biz"
Primary system configuration file is "startup-config"
Context switch load: 0.22%
Invoked Exec Time Runtime Load %%
Task Id Task Name PRI STA (count) (usec) (usec) (1sec)
1 Idle 0 W 5808802 490 468319 46.83
3 PC Config 7 S 15745801 276 414413 41.44
4 PacketRouting 44 W 3317891 70 26107 2.61
5 Timer 46 W 1028139 7 629 0.06
6 Timer-00 10 W 10587632 1 1415 0.14
7 Nm01 5 W 0 147678 0 0.00
8 Clock 9 W 33536 14 26 0.00
9 FrontPanel 43 W 216520 83 1660 0.17
10 con0 46 W 191 7 0 0.00
11 CF Manager 9 W 20974 5 9 0.00
12 ICP Session 8 W 1104 4 0 0.00
13 RSTP 43 W 109008 20 205 0.02
14 RSTP-BG 42 W 0 74 0 0.00
15 Thread Pool 4 W 17287 45 0 0.00
16 MLD Thread 6 W 4 4 0 0.00
17 RouteTableTick 6 W 10245 81 90 0.01
18 RouteTableTick 6 W 9587 34 34 0.00
19 IGMPTick 6 W 7013 21 21 0.00
20 IGMP-Receiver 6 W 0 499219 0 0.00
21 IP Events 27 W 69774 22 22 0.00
22 tcptimer 25 W 92481 10 77 0.01
23 tcpinp 25 W 172002 79 285 0.03
24 tcpout 25 W 633449 16 308 0.03
25 DnsClient 19 W 5536 22 0 0.00
26 DnsProxy 19 W 2204 10 0 0.00
27 DnsTable 19 W 2203 3 0 0.00
28 Port Manager 9 W 217935 30 631 0.06
29 PCI Bridge 32 W 109229 5 49 0.00
30 eth 0/1 46 W 1 1 0 0.00
31 giga-eth 0/1 46 W 20522239 3 46384 4.64
32 RSTP 43 W 0 78 0 0.00
33 giga-eth 0/2 46 W 18854100 2 29777 2.98
34 RSTP 43 W 0 69 0 0.00
35 SnmpThread 6 W 155234 5 157 0.02
36 WWW 22 W 2226 37 0 0.00
37 sec 46 W 1 0 0 0.00
38 IKE 6 W 648 87 0 0.00
39 IPSecKeyGen 4 W 0 53703 0 0.00
40 SCEP 6 W 0 49359 0 0.00
41 MediaConnectio~ 39 W 21608 155 432 0.04
42 FTPServer List~ 5 W 5 103 0 0.00
43 SMTP Client 19 W 0 38 0 0.00
44 SNTP Client 22 W 15 227 0 0.00
45 CLIInjectQ 6 W 0 13593 0 0.00
48 RipOut 6 W 6700 4 4 0.00
49 RipIn 6 W 0 12699 0 0.00
50 DHCP Server 34 W 22 145 0 0.00
51 UDP Relay 22 W 1 48 0 0.00
52 CFM Maint 44 W 11015 24 24 0.00
53 AUTOLINKQ 4 W 128 27 0 0.00
54 HttpClientQ 6 W 0 70 0 0.00
56 DHCPv6 34 W 0 222 0 0.00
57 Flow Meter Log~ 20 W 470938 9 6883 0.69
58 UDP In 42 W 20982 15 0 0.00
Thank you for asking this questions in the support community forum.
It is not recommended to have the firewall disabled on the ADTRAN unit that is on the public Internet. Here is the Security Best Practices for AOS Products guide.
Here is a post on what processes are included in the PC Config. thread: Re: what is the PC Config process in the show cpu output?
The reason the PC Config. thread could be high might be because of DoS attacks on DNS, NTP, or SNMP. If you would like to reply to this post with a copy of the current configuration (please, remember to remove any information that might be sensitive to the organization), I will be happy to review it for you.
Levi
Levi,
Thank you for the reply
You are right, the firewall is a good thing to implement normally. In this case it just needs to be a router. The only decision it needs to make is what interface the packets need to egress.
Shortly after posting my question, I downgraded back to 17.07.02 for fear of overloading unit. After downgrading CPU usage went back to below 50%, the normal for Sunday traffic.
Is their a possibility the newer release AOS is built for the newer 4430 generations?
Attached is a copy of the run. The VRRP is not implemented