[c-nsp] 3550 CPU Usage & IPSec

Gert Doering gert at greenie.muc.de
Fri Nov 21 06:31:00 EST 2008


Hi,

On Thu, Nov 20, 2008 at 02:15:15PM -0700, randal k wrote:
> The process is always IP Input. I'm pretty confident that it is IPSec
> traffic, as this customer's traffic is overwhelmingly the VPN tunnels;
> my 3550's CPU graph is an exact copy of his interface's traffic graph.

"something is weird".  Normally, the 3550 shouldn't care at all what
is inside those ISPEC packets, unless you have MTU issues and it needs
to do fragmentation.

Or are you running the IPSEC *on the 3550*?

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             gert at greenie.muc.de
fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 304 bytes
Desc: not available
URL: <https://puck.nether.net/pipermail/cisco-nsp/attachments/20081121/d844414e/attachment.bin>


More information about the cisco-nsp mailing list