[c-nsp] Bug ID CSCdy72539 For GRE Tunneling on 6500 PFC3B

Asbjorn Hojmark - Lists lists at hojmark.org
Thu Dec 7 17:10:57 EST 2006


> interface Tunnel2
>  ip mtu 1500 

I suspect that is your problem. If the underlying infrastructure
doesn't support 1500B + GRE (and it doesn't look like it from
your config), the packet needs to be fragmented and that will be
punted to the CPU.

I guess that's one situation where the IPSec module *will* take
over the tunnel then. 

-A



More information about the cisco-nsp mailing list