design hub-spokes policy

Unanswered Question
Aug 12th, 2008

I am trying to apply a policy in my PE router, wich is the interface with the mpls provider network. There is about 250 branches with 1 Mbps BW each one.

The most of the traffic is between the central poing and the branches.

I applied a policy in the interface of the PE router making shapping for each branch. The problem is that the router (7206vxr NPEG1) rise at 100 % of interrupt cpu.

Is another way to shape the traffic for each branch?



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Giuseppe Larosa Wed, 08/13/2008 - 09:18

Hello Marcelo,

may you post your configuration ?

have you enabled ip cef on your router and in your interface ?

have you tried to enable netflow that could help in flow classification ?

Are you using a single policy or nested policy with a parent policy and 250 child policies ? this could have a huge impact on performance.

Hope to help


MARCELO MATURO Wed, 08/13/2008 - 11:27

The cef is enable. I am using a nested policy with a parent and 250 child policies. There is another way to do it?



Giuseppe Larosa Wed, 08/13/2008 - 11:56

Hello Marcelo,

if using a single policy-map with 250 classes with shaper inside each class could have less impact

But I'm afraid it's too much anyway

Best Regards


MARCELO MATURO Wed, 08/13/2008 - 12:46

My config is like that:

policy-map Branches

class gre446

shape average 1024000

service-policy Suc446_P3_512

class gre143

shape average 1024000

service-policy Suc143_P3_512

class gre382

shape average 1024000

service-policy Suc382_P3_512

class gre384

shape average 1024000

service-policy Suc384_P3_512

class gre387

shape average 1024000

service-policy Suc387_P3_512

class gre386

shape average 512000

service-policy Suc386_P3_256

class gre020

shape average 1024000

service-policy Suc020_P3_512

class gre319

shape average 1024000

service-policy Suc319_P3_512

class gre044

shape average 1024000

service-policy Suc044_P3_512

class gre118

shape average 2048000

service-policy Suc118_P3_512


What's your opinion about to move the policy to the tunnel gre terminator, applying a single policy in each tunnel?



This Discussion