cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
843
Views
0
Helpful
8
Replies

Catalyst 4006/Sup III High CPU

eaaronseth
Level 1
Level 1

We have a Catalyst 4006 with a supervisor III that experiences high CPU (80-90%+) for periods of about 20 minutes. We are running IOS version Version 12.2(25)EWA14. We are running 2 OSPF processes on the box. One of the OSPF processes is running in a VRF (VRF Lite). I have checked traffic on the interfaces during the high CPU event and have seen nothing out of the ordinary. There have been no changes to the config that correlate with the start of the CPU spikes. During the high CPU SSH to the box is responsive. Based on the stated config/harware/ios; does anyone have any suggestions for things to check to try to pinpoint what is causing the high CPU?

8 Replies 8

glen.grant
VIP Alumni
VIP Alumni

jbrenesj
Level 3
Level 3

Please try to capture a:

sh proc cpu

sh plat health

During the high cpu period so we can investigate further about the cause

I attached the output of the above commands.

Thank you for the link to the document.

jbrenesj
Level 3
Level 3

Thanks, one particular process is really high:

IP Input

There are a couple of causes of this but first lets see if due to icmp redirects the cpu is spiking when there is more traffic.

I don't know if this is your case but normally the 4500 is the default-gateway for the hosts/servers and then you have some routers/firewalls on a separate vlan than the hosts that the 4500 redirects the traffic to.

Do you have routers/firewalls on the same vlan(subnet) than heavy traffic users or servers, if so, the 4500 may be sending icmp redirects back to the hosts so they use the router/firewall as the next-hop instead of the 4500. If this is the case then you can disable redirects on the interface vlans of the 4500

"no ip redirects"

Thank you for your reply.

We do have "no ip redirects" configured on the interface vlans. The 4000 does serve as the gateway for most of the networks in this area. The gateway is an HSRP address between 2 4000's. The routers/firewalls for these networks are on seperate VLANs.

Then it should be traffic being processed by software. try to set up a capture during the period of high util using this:

http://www.cisco.com/en/US/products/hw/switches/ps663/products_tech_note09186a00804cef15.shtml#tool2

I've attached the output from the following commands:

debug platform packet all receive buffer

show platform cpu packet statistics

Could try to clear all your counters and see if you are experiencing input/output drops during high cpu.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: