cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
202
Views
0
Helpful
1
Replies

VPN module wouldn't reduce CPU load???

jimmyjoseph
Level 1
Level 1

HI,

I had a Cisco 3640 router which i was using as a VPN gateway for two branch to branch Ipsec VPNs. Since the CPU utilization on this router was peaking out at times affecting the perfomance , I added a VPN encryption moudule to this router.

Now when i check the CPU utilization i don't see much difference..The average utilization used to be around 50% out of which 35 % used to be because of the encrypt process. Now after adding the module the average utilization is around 40% where as encrypt process is contributing zero. No other process

contributes significantly to the load.

There is something which i noticed. The parameter after "/" which is the load due to interrut process is almost same as the total process load for 5 sec utilization !!..is there anything going wrong?? How do i bring down the CPU load.

Attached is the out put of show process cpu.

Thanks and regards,

jimmy.

CPU utilization for five seconds: 54%/53%; one minute: 39%; five minutes: 39%

PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process

1 536 13296 40 0.00% 0.00% 0.00% 0 Load Meter

2 164 71 2309 0.00% 0.12% 0.03% 130 Virtual Exec

3 36064 7277 4955 0.00% 0.02% 0.01% 0 Check heaps

4 0 1 0 0.00% 0.00% 0.00% 0 Chunk Manager

5 0 2 0 0.00% 0.00% 0.00% 0 Pool Manager

6 0 2 0 0.00% 0.00% 0.00% 0 Timers

7 0 2 0 0.00% 0.00% 0.00% 0 Serial Backgroun

8 104 13276 7 0.00% 0.00% 0.00% 0 ALARM_TRIGGER_SC

9 0 1 0 0.00% 0.00% 0.00% 0 OIR Handler

10 28 2217 12 0.00% 0.00% 0.00% 0 Environmental mo

11 9568 19113 500 0.00% 0.00% 0.00% 0 ARP Input

12 336 3324 101 0.00% 0.00% 0.00% 0 HC Counter Timer

13 0 2 0 0.00% 0.00% 0.00% 0 DDR Timers

14 0 2 0 0.00% 0.00% 0.00% 0 Dialer event

15 0 2 0 0.00% 0.00% 0.00% 0 Entity MIB API

16 0 1 0 0.00% 0.00% 0.00% 0 SERIAL A'detect

17 0 1 0 0.00% 0.00% 0.00% 0 Critical Bkgnd

18 3712 31469 117 0.08% 0.00% 0.00% 0 Net Background

19 4 19 210 0.00% 0.00% 0.00% 0 Logger

20 1140 66453 17 0.08% 0.00% 0.00% 0 TTY Background

21 1588 66462 23 0.00% 0.00% 0.00% 0 Per-Second Jobs

PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process

22 0 2 0 0.00% 0.00% 0.00% 0 Hawkeye Backgrou

23 0 1 0 0.00% 0.00% 0.00% 0 HDV background

24 0 2 0 0.00% 0.00% 0.00% 0 VNM DSPRM MAIN

25 0 1 0 0.00% 0.00% 0.00% 0 Net Input

26 2660 13296 200 0.00% 0.00% 0.00% 0 Compute load avg

27 19464 1109 17550 0.00% 0.03% 0.00% 0 Per-minute Jobs

28 44 2217 19 0.00% 0.00% 0.00% 0 Call Management

29 0 1 0 0.00% 0.00% 0.00% 0 CES Line Conditi

30 0 2 0 0.00% 0.00% 0.00% 0 Service-module a

31 0 2 0 0.00% 0.00% 0.00% 0 ISDN Timer

32 0 1 0 0.00% 0.00% 0.00% 0 ISDN From Driver

33 3580 9773 366 0.00% 0.00% 0.00% 0 ecaimLoPri

34 0 2 0 0.00% 0.00% 0.00% 0 AAA Dictionary R

35 1968 4091 481 0.00% 0.03% 0.04% 0 IP Input

36 2464 8871 277 0.08% 0.00% 0.00% 0 CDP Protocol

37 0 1 0 0.00% 0.00% 0.00% 0 X.25 Encaps Mana

38 0 2 0 0.00% 0.00% 0.00% 0 PASVC create VA

39 0 2 0 0.00% 0.00% 0.00% 0 ATM OAM Input

40 0 2 0 0.00% 0.00% 0.00% 0 ATM OAM TIMER

41 0 1 0 0.00% 0.00% 0.00% 0 Asy FS Helper

42 0 1 0 0.00% 0.00% 0.00% 0 PPP IP Add Route

43 1848 1130 1635 0.00% 0.00% 0.00% 0 IP Background

PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process

44 80 1109 72 0.00% 0.00% 0.00% 0 Adj Manager

45 16 124 129 0.00% 0.00% 0.00% 0 TCP Timer

46 12 11 1090 0.00% 0.00% 0.00% 0 TCP Protocols

47 0 1 0 0.00% 0.00% 0.00% 0 Probe Input

48 0 1 0 0.00% 0.00% 0.00% 0 RARP Input

49 0 1 0 0.00% 0.00% 0.00% 0 HTTP Timer

50 0 1 0 0.00% 0.00% 0.00% 0 Socket Timers

51 0 2 0 0.00% 0.00% 0.00% 0 DHCPD Receive

52 96 1108 86 0.00% 0.00% 0.00% 0 IP Cache Ager

53 0 1 0 0.00% 0.00% 0.00% 0 COPS

54 0 1 0 0.00% 0.00% 0.00% 0 PAD InCall

55 4 2 2000 0.00% 0.00% 0.00% 0 X.25 Background

56 0 1 0 0.00% 0.00% 0.00% 0 SNMP Timers

57 0 1 0 0.00% 0.00% 0.00% 0 CES Client SVC R

58 116 112 1035 0.00% 0.00% 0.00% 0 Crypto HW Proc

59 16 47 340 0.00% 0.00% 0.00% 0 TACACS+

60 0 2 0 0.00% 0.00% 0.00% 0 CCVPM_HDSPRM

61 892 66457 13 0.00% 0.00% 0.00% 0 Net Serv Timer

62 228 192 1187 0.00% 0.00% 0.00% 0 Crypto Support

63 0 1 0 0.00% 0.00% 0.00% 0 Router Autoconf

64 0 1 0 0.00% 0.00% 0.00% 0 TSP

65 4 1 4000 0.00% 0.00% 0.00% 0 QOS_MODULE_MAIN

PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process

66 0 1 0 0.00% 0.00% 0.00% 0 CCVPM_HTSP

67 0 1 0 0.00% 0.00% 0.00% 0 CCVPM_R2

68 0 1 0 0.00% 0.00% 0.00% 0 CCSWVOICE

69 0 2 0 0.00% 0.00% 0.00% 0 Background Loade

70 0 1 0 0.00% 0.00% 0.00% 0 sssapp

71 4 5 800 0.00% 0.00% 0.00% 0 Crypto ACL

72 0 1 0 0.00% 0.00% 0.00% 0 Encrypt Proc

73 0 5 0 0.00% 0.00% 0.00% 0 Key Proc

74 0 1 0 0.00% 0.00% 0.00% 0 Crypto SSL

75 4 3 1333 0.00% 0.00% 0.00% 0 Crypto CA

76 2280 6158 370 0.00% 0.00% 0.00% 0 Crypto IKMP

77 772 10519 73 0.00% 0.00% 0.00% 0 IPSEC key engine

78 0 1 0 0.00% 0.00% 0.00% 0 IPSEC manual key

79 0 1 0 0.00% 0.00% 0.00% 0 ISDNMIB Backgrou

80 0 1 0 0.00% 0.00% 0.00% 0 CallMIB Backgrou

81 0 1 0 0.00% 0.00% 0.00% 0 Syslog Traps

82 356 6630 53 0.00% 0.00% 0.00% 0 BUSYOUT SCAN

83 612 66442 9 0.00% 0.00% 0.00% 0 trunk conditioni

84 0 1 0 0.00% 0.00% 0.00% 0 trunk conditioni

85 1392 2220 627 0.00% 0.00% 0.00% 0 IP SNMP

86 548 1110 493 0.00% 0.00% 0.00% 0 PDU DISPATCHER

87 2128 1110 1917 0.08% 0.00% 0.00% 0 SNMP ENGINE

PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process

88 0 1 0 0.00% 0.00% 0.00% 0 SNMP ConfCopyPro

89 0 1 0 0.00% 0.00% 0.00% 0 SNMP Traps

90 1200 66867 17 0.00% 0.00% 0.00% 0 NTP

91 4 554 7 0.00% 0.00% 0.00% 0 DHCPD Timer

92 40 18821 2 0.00% 0.00% 0.00% 0 DHCPD Database

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

your CPU load is 99% due to interrupts, not to traffic (54%/53% means the CPU is 54% busy, and that 53% of it is due to interrupts). Installing the VPN card has reduced the CPU load due to the IPSec traffic, but your underlying problem is that the CPU is being interrupted all the time. You'll notice that there's no one process that seems to be using up all the CPU, that's because the load is not process related.

A good resource for fixing CPU problems is here:

http://www.cisco.com/en/US/products/sw/iosswrel/ps1828/products_tech_note09186a00800a70f2.shtml

Basically check your switching paths, make sure you have CEF enabled and "ip route-cache" on every interface. Check how much traffic this router is receiving, it may just be overloaded.