cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
232
Views
0
Helpful
2
Replies

CPU on 2621 limit

cmhcsys
Level 1
Level 1

We have a 2621 Router on the edge of our network. It has 2 bonded T-1’s to the Internet and uses 1 Fast Ethernet to connect to our internal router. The 2621 router has a large access list for incoming connections, basically it is our firewall. (Before you tell me about how bad this is to do, let me say I know and I have been trying to fix it since I started here.)

Any way. To my limits question. With running this large access list on the 2621 we have now gotten to a point that the average CPU usage during the day is running in the 80% range on the 60 minute graph.(show processor cpu history command) The bad part is that the Max CPU on that same graph is hitting 99%.

My Question is, at what % on the CPU did the router start dropping things. Someone in MGT is trying to say they read it is 92-93% before it starts dieing and we are fine with the 80% range. Basically they are dragging there feet from not getting the PIX that I requested some time back.

Sorry for the long-winded dump here.

Thanks to anyone that can help me answer this question

2 Replies 2

Hello,

I do not think that there is a clear-cut formula for this; usually, when CPU utilization is too high you will get symptoms like like a slow response in Telnet or being unable to Telnet to the router, a slow response on the console, a slow or no response to ping, or you will see that the router doesn't send routing updates to other routers. But a utilization of 80% on average with peaks of 99% is definitely good. I had a very similar situation (on a 2600 as well) a while ago, and I could only lighten the CPU utilization by rate-limiting the traffic. Which process(es) is or are causing the utilization ? And are you sure that you don´t have a virus like Nimda or Nacho ? Can you post the config of your router ?

Regards,

GP

I'm sure I don't have a virus. We were lucky or good on being proactive for them. I did have one of my mobel sales people bring in an infected laptop and for the short time that it was on my network it dropped my 2621 router to the point of what you where discribing. Slow to no responce, not routing, etc.... I have MRTG polling it on a 5min cycle and it was maxed 100% CPU usage during that time. It took us about 15min to find it and clean 3 others that got infected during that time.

I will try to get a config to post. I just don't know if it will fit in the 10,000 char post limit.

Thank for your time

TH