05-07-2009 02:42 AM - edited 03-04-2019 04:40 AM
Hi,
I currently have a GRE/IPSec tunnel setup between 2 2611XM routers with 4 Mbs bandwidth between the 2 sites. When transferring data between the 2 sites I get around 90Kbs over the GRE/IPSec tunnels and the CPU usage maxes out during the data transfer. Without IPsec I get usage of the full bandwidth.
I'm looking to replace these routers with a couple of Cisco 1812's or maybe even Cisco 871's, as this link is only a backup.
Does anyone know what the performance of these 2 routes is like with reagrds to GRE/IPSEC?
Thanks
05-07-2009 02:49 AM
Have you tried adjusting the MTU to accomodate the larger packets? With the added overhead of IPSec and GRE, your packets may be getting fragmented, causing delay and CPU overutilization.
http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml
HTH
Victor
05-07-2009 03:14 AM
05-07-2009 05:06 AM
Thanks for this. My 2611XM doesn't have an encryption module. According to the spec sheet the 3DES performance almost doubles between the 2600XM's and the 1800's, which is promising. Although if I get less than 1Mbs currently, what does this say about what I'm likely to get on the 1800!
For now, I've actually offloaded the IPSec tunnel onto a PIX which is sat infront of the router and just kept the GRE tunnel at the 2600XM, which works well. But I'd like have both on one device for simplicity's sake.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide