2621XM connection speed

Answered Question

When I connect my PC directly to the cable modem I get about 20Mb/s

When I connect my PC through the 2621XM I get around 10Mb/s


Is this because the 2621XM can't handle the throughput or do I have something wrong with my config?


version 12.4
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname BYRD-RTR
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 3 log
no logging buffered
enable secret 5 ************
!
no aaa new-model
clock timezone EST -5
clock summer-time EST-DLS recurring
voice-card 0
no dspfarm
no local-bypass
!
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.10.1 192.168.10.99
ip dhcp excluded-address 192.168.10.200 192.168.10.254
!
ip dhcp pool Ronald
host 192.168.10.100 255.255.255.0
client-identifier 0100.13d4.800b.a1
default-router 192.168.10.1
option 42 ip 192.168.10.1
dns-server 68.87.74.162 68.87.68.162
!
ip dhcp pool CAM
host 192.168.10.201 255.255.255.0
client-identifier 0100.1346.dae7.ae
default-router 192.168.10.1
dns-server 68.87.74.162 68.87.68.162
!
ip dhcp pool LAN_HOSTS
network 192.168.10.0 255.255.255.0
default-router 192.168.10.1
option 42 ip 192.168.10.1
dns-server 68.87.74.162 68.87.68.162
!
!
ip name-server 68.87.74.162
ip name-server 68.87.68.162
ip inspect name SDM_LOW cuseeme
ip inspect name SDM_LOW dns
ip inspect name SDM_LOW ftp
ip inspect name SDM_LOW h323
ip inspect name SDM_LOW https
ip inspect name SDM_LOW icmp
ip inspect name SDM_LOW imap
ip inspect name SDM_LOW pop3
ip inspect name SDM_LOW netshow
ip inspect name SDM_LOW rcmd
ip inspect name SDM_LOW realaudio
ip inspect name SDM_LOW rtsp
ip inspect name SDM_LOW esmtp
ip inspect name SDM_LOW sqlnet
ip inspect name SDM_LOW streamworks
ip inspect name SDM_LOW tftp
ip inspect name SDM_LOW tcp
ip inspect name SDM_LOW udp
ip inspect name SDM_LOW vdolive
ip inspect name SDM_LOW l2tp
ip inspect name SDM_LOW pptp
ip inspect name SDM_LOW ipsec-msft
!
multilink bundle-name authenticated
!
!
!
no voice call carrier capacity active
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
crypto pki trustpoint TP-self-signed-2483364401
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2483364401
revocation-check none
rsakeypair TP-self-signed-2483364401
!
!
crypto pki certificate chain TP-self-signed-2483364401
certificate self-signed 01
  30820255 308201BE A0030201 02020101 300D0609 2A864886 F70D0101 04050030
  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
  69666963 6174652D 32343833 33363434 3031301E 170D3130 30343036 30313231
  34375A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 34383333
  36343430 3130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
  8100C316 93A4C524 9069E078 DA45EDC4 6A17920C 435C3E33 20731958 74BDAB4B
  84C30DE0 BD31B832 F5EA52EC 3B644DB3 DD557738 1642CCB7 8D6FE30B 1359F330
  2EEEB5FE E6E98AAB FF3ED77A D9B9AE29 D650222C 468A1E44 43427333 9F0F92B3
  5CF47FC7 FBB79C65 E3E66940 94908AE4 3E1726C5 D11B6C03 3D15FF31 41834DD2
  B0E10203 010001A3 7D307B30 0F060355 1D130101 FF040530 030101FF 30280603
  551D1104 21301F82 1D425952 442D5254 522E6873 64312E66 6C2E636F 6D636173
  742E6E65 742E301F 0603551D 23041830 1680147E C4C73356 3854422E 5E34E2DF
  C8283D57 011D4630 1D060355 1D0E0416 04147EC4 C7335638 54422E5E 34E2DFC8
  283D5701 1D46300D 06092A86 4886F70D 01010405 00038181 007D4934 036BDA14
  9CD6CC05 A5805858 FF5886BA 59166AD3 FBBF7E89 68494F1F 29740239 A04D8D5A
  4C634A8A 923E7032 10F38AF4 C49A54E5 DAD5C542 EED0B862 464AE31A B7034907
  8F797BAE 77378445 6FFC66F8 E61C5B82 381F42A3 154C88F9 8994B070 59A52940
  90080EB5 AC0AC0E3 448EE56B 5AE2411B 1FA9B635 A1E51946 37
  quit
!
!
username ronald privilege 15 password 7 094B5D110B
archive
log config
  hidekeys
!
!
!
!
ip tcp synwait-time 10
!
!
!
!
interface Loopback0
no ip address
!
interface Null0
no ip unreachables
!
interface FastEthernet0/0
description $ETH-WAN$$FW_OUTSIDE$
ip address x.x.x.233 255.255.255.248
ip access-group 102 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat outside
ip virtual-reassembly
ip route-cache flow
speed auto
full-duplex
no cdp enable
no mop enabled
!
interface FastEthernet0/1
description $ETH-LAN$$FW_INSIDE$
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
speed auto
full-duplex
no mop enabled
!
interface FastEthernet0/1.1
description VLAN 1
encapsulation dot1Q 1 native
ip address 192.168.10.1 255.255.255.0
ip access-group 110 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nat inside
ip inspect SDM_LOW in
ip virtual-reassembly
!
interface FastEthernet1/0
ip address 192.168.11.1 255.255.255.0
duplex auto
speed auto
!
router rip
version 2
network 192.168.10.0
network 192.168.11.0
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 x.x.x.238
!
ip flow-cache timeout active 1
!
no ip http server
ip http access-class 1
ip http authentication local
ip http secure-server
ip dns server
ip nat inside source static tcp 192.168.10.100 8080 interface FastEthernet0/0 8080
ip nat inside source static tcp 192.168.10.100 3389 interface FastEthernet0/0 3389
ip nat inside source static tcp 192.168.10.100 2600 interface FastEthernet0/0 2600
ip nat inside source static udp 192.168.10.100 2600 interface FastEthernet0/0 2600
ip nat inside source static tcp 192.168.10.201 80 interface FastEthernet0/0 80
ip nat inside source route-map LAN interface FastEthernet0/0 overload
ip nat inside source static 192.168.11.2 x.x.x.234
!
access-list 1 remark VLAN1
access-list 1 permit 192.168.10.0 0.0.0.255
access-list 1 permit 192.168.11.0 0.0.0.255
access-list 1 deny any
access-list 102 remark WAN IN ACL
access-list 102 permit udp any eq bootps any eq bootpc
access-list 102 permit icmp any any echo-reply
access-list 102 permit icmp any any time-exceeded
access-list 102 permit icmp any any unreachable
access-list 102 permit tcp any any eq 3389
access-list 102 permit tcp any any eq www
access-list 102 permit tcp any any eq 8080
access-list 102 permit tcp any any eq 2600
access-list 102 permit tcp any any eq whois
access-list 102 permit udp any any eq 2600
access-list 102 permit udp any any eq ntp
access-list 102 deny ip any any
access-list 110 remark VLAN1 IN ACL
access-list 110 permit ip any any
snmp-server community public RO
snmp-server community private RW
!
!
!
route-map LAN permit 1
match ip address 1
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
!
line con 0
transport output telnet
line aux 0
transport output telnet
line vty 0 4
access-class 1 in
exec-timeout 0 0
password 7 ************
logging synchronous
login
transport input telnet
!
scheduler allocate 4000 1000
ntp clock-period 17180086
ntp master 2
ntp peer 129.6.15.28
!
end

Correct Answer by Jon Marshall about 6 years 11 months ago

With CEF switching the 2621XM should give around a maximum of 15Mbps of throughput but obviously with things like IOS firewall (CBAC),  NAT etc. then this will be somewhat reduced so i don't think you are that far out.


See the attached router performance sheet for details.


Jon

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Jon Marshall Wed, 04/07/2010 - 16:40
User Badges:
  • Super Blue, 32500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

With CEF switching the 2621XM should give around a maximum of 15Mbps of throughput but obviously with things like IOS firewall (CBAC),  NAT etc. then this will be somewhat reduced so i don't think you are that far out.


See the attached router performance sheet for details.


Jon

Actions

This Discussion