I want to use some of the IOS firewall features on the 2851 but have some questions on CPU impact. I use this device for IPSec termination which also incorporates some NAT. It seems that when NAT is enabled, packets traversing interfaces that have NAT enabled are process switched which hits the CPU as well as throughput. I use BGP on this router with low timers and if the CPU ever hit 100%, it is very possible that BGP would flap. I will be building this in a lab in the next few weeks but thought I would ask the experts their advise on which if any features are processed by the CPU instead by an ASIC.
Thanks for any feedback