Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

MLS x CEF in switch 6500

Good afternoon gentlemen


Even searching some articles regarding MLS configuration and CEF configuration, both concepts are still not clear for me.

We have a 6509E switch with supervisor 720, with submodules PFC3B and MSFC3. IOS is 12.2(33)SXJ7.

Sometimes we face some high CPU usage due to IP Input and SNMP process and issuing "show run".

CEF is enable globally ("ip cef distributed") and for each interface VLAN ("ip route-cache cef")

MLS is enabled for QOS ("mls qos") for configuring policy-maps for policing traffic input and output in interface vlans. Configured "mls qos vlan-based" in physical interfaces associated to those VLANs.

There's a access-list applied in line vty with an ending deny and logging lots of attempts not allowed in switch.



Each interface VLAN has the following remaining configuration:

no mls ip
no mls switching unicast


Some remaining configuration I found in switch:

no mls ipv6 acl pbr svi hardware
no mls acl tcam override dynamic dhcp-snooping
no mls acl tcam override dynamic dai
no mls acl tcam share-acl
no mls acl tcam share-global
mls netflow interface
mls cef error action reset




1 - Is there any tuning or best practices I could perform in switch configuration regarding mls and cef?


2 - What's the difference regarding "mls cef" and "ip cef" for comand "show" for troubleshooting?






Everyone's tags (1)

Hi there, I remember when i

Hi there,


I remember when i faced the same problem on 6500 related to snmp and TAC advised me to upgrade the IOS.

Better to check with TAC for any bugs.




New Member

Interesting that I have just

Interesting that I have just upgraded the IOS to the last version 12 release.

I think that for the reason that we are facing high CPU usage for "IP Input" process, something related to mls/cef is not tunned.

Anyone has any idea regarding the configuration presented?




Hi Christian,Some insight for

Hi Christian,

Some insight for traffic qualified as IP Input:



New Member

Though I've already

Though I've already configured CEF globally and by interface vlan, when I enable "mls ip" and "mls switching unicast" in those interface VLANs, CPU has decreased from above 70% to 20%.