cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
277
Views
0
Helpful
1
Replies

Policy Based Routing in vrf on Cat6500 Sup720

Svante Bolander
Level 1
Level 1

We are utilizing PBR on SVIs that are in a vrf on cat6500/Sup720B. An route-map with an acl like "<ip-net> to any" is configured and a match sets ip next-hop to a gateway on a directly connected network. This works most times fine and we can send traffic from specified source addresses to a different next-hop than the routing table dictates.

But we now suspects that this traffic is cpu-proccessed since the cpu is rather high on the Sup720.

The questions are: Are PBR in a vrf CPU-processed? Any improvements to be done on PBR in vrfs?

1 Reply 1

Not applicable

I think when the TCAM is running out of space, VRF processing is changed from hardware to software.

This Can increase the CPU utilization.

A IPSec VPN Services Module is recommended, or tuning the ACL of the PBR can improve the situation.

http://www.cisco.com/en/US/products/hw/modules/ps2706/products_data_sheet09186a00800c4fe2.html

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: