01-28-2003 01:34 PM - edited 02-21-2020 12:18 PM
HI,
I had a Cisco 3640 router which i was using as a VPN gateway for two branch to branch Ipsec VPNs. Since the CPU utilization on this router was peaking out at times affecting the perfomance , I added a VPN encryption moudule to this router.
Now when i check the CPU utilization i don't see much difference..The average utilization used to be around 50% out of which 35 % used to be because of the encrypt process. Now after adding the module the average utilization is around 40% where as encrypt process is contributing zero. No other process
contributes significantly to the load.
There is something which i noticed. The parameter after "/" which is the load due to interrut process is almost same as the total process load for 5 sec utilization !!..is there anything going wrong?? How do i bring down the CPU load.
Attached is the out put of show process cpu.
Thanks and regards,
jimmy.
CPU utilization for five seconds: 54%/53%; one minute: 39%; five minutes: 39%
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
1 536 13296 40 0.00% 0.00% 0.00% 0 Load Meter
2 164 71 2309 0.00% 0.12% 0.03% 130 Virtual Exec
3 36064 7277 4955 0.00% 0.02% 0.01% 0 Check heaps
4 0 1 0 0.00% 0.00% 0.00% 0 Chunk Manager
5 0 2 0 0.00% 0.00% 0.00% 0 Pool Manager
6 0 2 0 0.00% 0.00% 0.00% 0 Timers
7 0 2 0 0.00% 0.00% 0.00% 0 Serial Backgroun
8 104 13276 7 0.00% 0.00% 0.00% 0 ALARM_TRIGGER_SC
9 0 1 0 0.00% 0.00% 0.00% 0 OIR Handler
10 28 2217 12 0.00% 0.00% 0.00% 0 Environmental mo
11 9568 19113 500 0.00% 0.00% 0.00% 0 ARP Input
12 336 3324 101 0.00% 0.00% 0.00% 0 HC Counter Timer
13 0 2 0 0.00% 0.00% 0.00% 0 DDR Timers
14 0 2 0 0.00% 0.00% 0.00% 0 Dialer event
15 0 2 0 0.00% 0.00% 0.00% 0 Entity MIB API
16 0 1 0 0.00% 0.00% 0.00% 0 SERIAL A'detect
17 0 1 0 0.00% 0.00% 0.00% 0 Critical Bkgnd
18 3712 31469 117 0.08% 0.00% 0.00% 0 Net Background
19 4 19 210 0.00% 0.00% 0.00% 0 Logger
20 1140 66453 17 0.08% 0.00% 0.00% 0 TTY Background
21 1588 66462 23 0.00% 0.00% 0.00% 0 Per-Second Jobs
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
22 0 2 0 0.00% 0.00% 0.00% 0 Hawkeye Backgrou
23 0 1 0 0.00% 0.00% 0.00% 0 HDV background
24 0 2 0 0.00% 0.00% 0.00% 0 VNM DSPRM MAIN
25 0 1 0 0.00% 0.00% 0.00% 0 Net Input
26 2660 13296 200 0.00% 0.00% 0.00% 0 Compute load avg
27 19464 1109 17550 0.00% 0.03% 0.00% 0 Per-minute Jobs
28 44 2217 19 0.00% 0.00% 0.00% 0 Call Management
29 0 1 0 0.00% 0.00% 0.00% 0 CES Line Conditi
30 0 2 0 0.00% 0.00% 0.00% 0 Service-module a
31 0 2 0 0.00% 0.00% 0.00% 0 ISDN Timer
32 0 1 0 0.00% 0.00% 0.00% 0 ISDN From Driver
33 3580 9773 366 0.00% 0.00% 0.00% 0 ecaimLoPri
34 0 2 0 0.00% 0.00% 0.00% 0 AAA Dictionary R
35 1968 4091 481 0.00% 0.03% 0.04% 0 IP Input
36 2464 8871 277 0.08% 0.00% 0.00% 0 CDP Protocol
37 0 1 0 0.00% 0.00% 0.00% 0 X.25 Encaps Mana
38 0 2 0 0.00% 0.00% 0.00% 0 PASVC create VA
39 0 2 0 0.00% 0.00% 0.00% 0 ATM OAM Input
40 0 2 0 0.00% 0.00% 0.00% 0 ATM OAM TIMER
41 0 1 0 0.00% 0.00% 0.00% 0 Asy FS Helper
42 0 1 0 0.00% 0.00% 0.00% 0 PPP IP Add Route
43 1848 1130 1635 0.00% 0.00% 0.00% 0 IP Background
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
44 80 1109 72 0.00% 0.00% 0.00% 0 Adj Manager
45 16 124 129 0.00% 0.00% 0.00% 0 TCP Timer
46 12 11 1090 0.00% 0.00% 0.00% 0 TCP Protocols
47 0 1 0 0.00% 0.00% 0.00% 0 Probe Input
48 0 1 0 0.00% 0.00% 0.00% 0 RARP Input
49 0 1 0 0.00% 0.00% 0.00% 0 HTTP Timer
50 0 1 0 0.00% 0.00% 0.00% 0 Socket Timers
51 0 2 0 0.00% 0.00% 0.00% 0 DHCPD Receive
52 96 1108 86 0.00% 0.00% 0.00% 0 IP Cache Ager
53 0 1 0 0.00% 0.00% 0.00% 0 COPS
54 0 1 0 0.00% 0.00% 0.00% 0 PAD InCall
55 4 2 2000 0.00% 0.00% 0.00% 0 X.25 Background
56 0 1 0 0.00% 0.00% 0.00% 0 SNMP Timers
57 0 1 0 0.00% 0.00% 0.00% 0 CES Client SVC R
58 116 112 1035 0.00% 0.00% 0.00% 0 Crypto HW Proc
59 16 47 340 0.00% 0.00% 0.00% 0 TACACS+
60 0 2 0 0.00% 0.00% 0.00% 0 CCVPM_HDSPRM
61 892 66457 13 0.00% 0.00% 0.00% 0 Net Serv Timer
62 228 192 1187 0.00% 0.00% 0.00% 0 Crypto Support
63 0 1 0 0.00% 0.00% 0.00% 0 Router Autoconf
64 0 1 0 0.00% 0.00% 0.00% 0 TSP
65 4 1 4000 0.00% 0.00% 0.00% 0 QOS_MODULE_MAIN
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
66 0 1 0 0.00% 0.00% 0.00% 0 CCVPM_HTSP
67 0 1 0 0.00% 0.00% 0.00% 0 CCVPM_R2
68 0 1 0 0.00% 0.00% 0.00% 0 CCSWVOICE
69 0 2 0 0.00% 0.00% 0.00% 0 Background Loade
70 0 1 0 0.00% 0.00% 0.00% 0 sssapp
71 4 5 800 0.00% 0.00% 0.00% 0 Crypto ACL
72 0 1 0 0.00% 0.00% 0.00% 0 Encrypt Proc
73 0 5 0 0.00% 0.00% 0.00% 0 Key Proc
74 0 1 0 0.00% 0.00% 0.00% 0 Crypto SSL
75 4 3 1333 0.00% 0.00% 0.00% 0 Crypto CA
76 2280 6158 370 0.00% 0.00% 0.00% 0 Crypto IKMP
77 772 10519 73 0.00% 0.00% 0.00% 0 IPSEC key engine
78 0 1 0 0.00% 0.00% 0.00% 0 IPSEC manual key
79 0 1 0 0.00% 0.00% 0.00% 0 ISDNMIB Backgrou
80 0 1 0 0.00% 0.00% 0.00% 0 CallMIB Backgrou
81 0 1 0 0.00% 0.00% 0.00% 0 Syslog Traps
82 356 6630 53 0.00% 0.00% 0.00% 0 BUSYOUT SCAN
83 612 66442 9 0.00% 0.00% 0.00% 0 trunk conditioni
84 0 1 0 0.00% 0.00% 0.00% 0 trunk conditioni
85 1392 2220 627 0.00% 0.00% 0.00% 0 IP SNMP
86 548 1110 493 0.00% 0.00% 0.00% 0 PDU DISPATCHER
87 2128 1110 1917 0.08% 0.00% 0.00% 0 SNMP ENGINE
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
88 0 1 0 0.00% 0.00% 0.00% 0 SNMP ConfCopyPro
89 0 1 0 0.00% 0.00% 0.00% 0 SNMP Traps
90 1200 66867 17 0.00% 0.00% 0.00% 0 NTP
91 4 554 7 0.00% 0.00% 0.00% 0 DHCPD Timer
92 40 18821 2 0.00% 0.00% 0.00% 0 DHCPD Database
01-28-2003 06:09 PM
your CPU load is 99% due to interrupts, not to traffic (54%/53% means the CPU is 54% busy, and that 53% of it is due to interrupts). Installing the VPN card has reduced the CPU load due to the IPSec traffic, but your underlying problem is that the CPU is being interrupted all the time. You'll notice that there's no one process that seems to be using up all the CPU, that's because the load is not process related.
A good resource for fixing CPU problems is here:
http://www.cisco.com/en/US/products/sw/iosswrel/ps1828/products_tech_note09186a00800a70f2.shtml
Basically check your switching paths, make sure you have CEF enabled and "ip route-cache" on every interface. Check how much traffic this router is receiving, it may just be overloaded.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide