[nsp] Breaking out components of IP Input process

Siva Valliappan svalliap at cisco.com
Thu Dec 19 17:09:06 EST 2002


what version of code are you running?  there was an old bug that would
cause us to process switch GRE-in-IPSec traffic.  you should actually
be able to CEF / Fast-switch the traffic with the encryption offloaded to
the AIM.

cheers
.siva

On Thu, 19 Dec 2002 rpcbind@speakeasy.net wrote:

>
> I'm doing GRE-in-IPSec on a 3660 and am pegging CPU at around 15mb/s (w/
> AIM-VPN/HP). My guess is this is all going to tunnel encapsulation -- is there
> good way to verify that? I'd like to squeeze more out of it, and the new
> AIM-VPN/HPII is appealing, but not if I'll need to bump CPU to handle the
> GRE...
>
> Ideas?
>
> Thanks.
>
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp@puck.nether.net
> http://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
>


More information about the cisco-nsp mailing list