Skip to main content
bobm
New Member
August 28, 2017
Question

5.2 vs 5.4 CPU usage

  • August 28, 2017
  • 2 replies
  • 17580 views

Hi,

I know we're behind the curve, but I'm looking at finally upgrading our 90D to FW 5.4.x in the near future.  Right now we're running 5.2.7, but I think some of the 5.4 logging and reporting abilities would really be useful.

 

The issue is, though, that our 90D is really too small for our environment.  We have 40-50 users running data and voice, with Web Filtering and load balanced WAN.  I had to turn IPS off because the CPU kept spiking, and even now it spends way too much time in the 60-80% range for my taste. 

 

So my question is, how does CPU utilization compare between 5.2 and 5.4 for these small boxes? Is there a version of 5.4 that seems to be better than others for CPU efficiency? Or will 5.4 just completely overwhelm the box as I have it?

 

Thanks

    2 replies

    MikePruett
    New Member
    August 28, 2017

    My utilization got a little better. That being said, you definitely want to upgrade that 90D. I had one in a smaller environment and hated it.

    bobm
    bobmAuthor
    New Member
    August 28, 2017

    OK, thanks

    bobm
    bobmAuthor
    New Member
    September 14, 2017

    OK, got the box up to 5.2.11 this morning seemingly OK (I thought the suggested path was 5.2.7-5.2.9-5.2.11 but the box told me to go straight to 11). Now to upgrade to 5.4 in the next week or two so we're only one major rev behind.

     

    Any recommendations on which 5.4 build will be most stable,  least disruptive and best use of limited resources?

     

    Thanks

    btp
    New Member
    November 20, 2017

    I upgraded a FG60D HA running at 5.2.7. to 5.4.6, due to some bugs that have been around until this release (BGP/IPSEC and hardware offloading). We use BFD to shorten failover-time in case of fail, and with the default settings the route kept flapping when traffic increased. The CPU was overwhelmed.

     

    For this particular setup there was no BFD before, so I can't really say that it was the new firmware that did this - but it runs fine other places on 5.2.7.