On the 3945e, no issues are seen. On this platform, the encryption/decryption queue most of the time empty.
3945e-1#sh crypto engine accelerator ring pool
Device: Onboard VPN
Location: Onboard: 0
The Crypto Packet IPSEC Queue Information
The Queuesize is :2048
The no of entries currently being used : 0
The Read Index is :1809
The Write Index is :1809
Even if on 5 seconds average, the CPU usage is not at 90+%, the nature of the traffic can create a port speed burst that lasts few msec.
During that time, a router may have issues polling each interface [ which leads to overruns].
Always size your router accordingly to the nature of the traffic or shape the flow on the next hop device on the LAN side [ in order to queue packets instead of dropping them as overruns on the ipsec gateway.