cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
301
Views
0
Helpful
1
Replies

Cisco IOS Firewalling on a 2851

adamclarkuk_2
Level 4
Level 4

Hi All

I want to use some of the IOS firewall features on the 2851 but have some questions on CPU impact. I use this device for IPSec termination which also incorporates some NAT. It seems that when NAT is enabled, packets traversing interfaces that have NAT enabled are process switched which hits the CPU as well as throughput. I use BGP on this router with low timers and if the CPU ever hit 100%, it is very possible that BGP would flap. I will be building this in a lab in the next few weeks but thought I would ask the experts their advise on which if any features are processed by the CPU instead by an ASIC.

Thanks for any feedback

1 Reply 1

bapatsubodh
Level 1
Level 1

Hi,

1. IPSEC

2. NAT

3.BGP

In these processes IPSEC and BGP are CPU intensive processes. Most likely those are processed by CPU. But ultimately CPU usage depends upon how much traffic is processed in a unit time. If you have rough idea about how much traffic is likely to be encrypted or how big BGP routing table is ( depends upon BGP implementation ) then you can possibly decide if 2851 would hit 100 % cpu utilization.

If possible you can try with VPN accelerator cards. Those really comes handy when hudge amount of traffic is processsed by IPSEC.

HTH.

Please rate if possible

Thanks

Subodh

Review Cisco Networking products for a $25 gift card