cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
774
Views
0
Helpful
2
Replies

3750 port-security, arp inspection, dhcp snooping CPU HOG

Nicholas Poole
Level 1
Level 1

Stack of five C3750 switches running 12.2(25)SEB4.

Security features on the port are:

port-security (restrict 3 mac)

DHCP snooping (with dhcp pool on the switch)

Dynamic ARP Inspection/DAI

As reccommended in the config guide.

The problem is upon reload, albeit cold start or warm start, the CPU runs at 100%. The process that is reporting the problems is Logger initially:

-show proc cpu

CPU utilization for five seconds: 100%/1%; one minute: 94%; five minutes: 51%

24 189319 184 1028907 69.76% 69.47% 35.80% 0 Logger

%SYS-3-CPUHOG: Task is running for (2098)msecs, more than (2000)msecs (2/1),process = Logger

When I turn off logging, I can then see the DAI process as the cause by issuing a show proc cpu again:

121 726073 6256 116060 88.15% 87.78% 77.38% 0 HRPC dai request

It took 25 minutes for a nearly fully populated stack of 5xC3750-48 switch with 7940's and PC's, to stabilise. Phones slowly started to load and the CPU suddenly drops to 30% and then to its normal 10%:

CPU utilization for five seconds: 100%/1%; one minute: 94%; five minutes: 51%

This is bad enough and it looks like a problem with the DAI process. But the odd thing is that in the lab I have recreated this problem and the resolution doesnt seem to be turning of DAI, but turning off port security?!?!? Even though port security isnt listed as a problem process.

Yet another 3750 bug?

2 Replies 2

Prashanth Krishnappa
Cisco Employee
Cisco Employee

I did not find any known bug. Can you post your config from lab and procedure you use to recreate the problem?

running config of test lab (which is an empty office)stack of 3 switches.