Cisco ASA - SCP causes orphaned ssh_init processes


This is a nasty little big I found the other day which hopefully you can avoid after reading this article.

When using SCP to copy a file to/from the ASA that is over 100k the transfer stalls and then fails. This results in an orphaned ssh_init process. Each ssh_init process then still occupies a CPU footprint causing the overall CPU usage of the device to rise.

So if you try 3 or 4 times to get the transfer to work you can easily end up adding 50-60% to the overall CPU of the box. Which isn't great is the box is already seeing a healthy amount of traffic. Unfortunately the only method to clear these orphaned processes is to reboot the box.

On top of this as the ASA only permits a maximum of 5 SSH sessions should you have 5 orphaned ssh_init processes, then you will be locked out from being able to SSH into the device.


Either upgrade to 8.0(5.24) or 8.2(5). Or avoid using SCP and instead use TFTP, FTP or HTTP.


Further details can be viewed at

Tags: ASA