10-29-2013 06:38 PM - edited 03-04-2019 09:26 PM
I have a Cisco 2620xm router behind ATT Uverse router..I get 11Mbps then it drops to 5Mbps
When I go from ATT Router to switch I get the full 12Mbps.....
CPU does not go over 30%.....
I tried different Speed/Duplex settings
When I reboot the Cisco router I get back to 11Mbps then it drops
I tried a different Cisco IOS and no luck.
stinger#sh ver
Cisco IOS Software, C2600 Software (C2600-ADVENTERPRISEK9-M), Version 12.4(25d), RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Wed 18-Aug-10 04:49 by prod_rel_team
ROM: System Bootstrap, Version 12.2(8r) [cmong 8r], RELEASE SOFTWARE (fc1)
stinger uptime is 6 minutes
System returned to ROM by reload at 20:04:54 CDT Tue Oct 29 2013
System restarted at 20:09:52 CDT Tue Oct 29 2013
System image file is "flash:c2600-adventerprisek9-mz.124-25d.bin"
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
export@cisco.com.
Cisco 2620XM (MPC860P) processor (revision 2.0) with 221184K/40960K bytes of memory.
Processor board ID JAE08020Z8A
M860 processor: part number 5, mask 2
2 FastEthernet interfaces
1 Serial interface
1 ATM interface
1 Virtual Private Network (VPN) Module
32K bytes of NVRAM.
49152K bytes of processor board System flash (Read/Write)
Configuration register is 0x3922
!
! No configuration change since last restart
!
version 12.4
parser config cache interface
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec show-timezone
service password-encryption
service sequence-numbers
!
hostname stinger
!
boot-start-marker
boot-end-marker
!
logging count
logging buffered 10000 debugging
logging rate-limit 10000
logging console informational
logging monitor informational
enable secret 5 xxxxxx
enable password 7 xxxxxxx
!
aaa new-model
!
!
aaa authentication login local_auth local
!
aaa session-id common
memory-size iomem 15
clock timezone CST -6
clock summer-time CDT recurring
no network-clock-participate slot 1
no network-clock-participate wic 0
no ip source-route
no ip gratuitous-arps
ip cef
!
!
!
!
no ip bootp server
ip domain name drichwalski.net
ip name-server 192.168.0.1
ip name-server 192.168.0.10
ip inspect name SDM_LOW ftp
ip inspect name SDM_LOW tcp
ip inspect name SDM_LOW udp
ip inspect name SDM_LOW dns
ip inspect name SDM_LOW https
ip inspect name SDM_LOW icmp
ip inspect name SDM_LOW imap
ip inspect name SDM_LOW pop3
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
ip ips sdf location flash://256MB.sdf autosave
ip ips notify SDEE
ip ips name sdm_ips_rule
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
crypto pki trustpoint TP-self-signed-3030517303
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3030517303
revocation-check none
rsakeypair TP-self-signed-3030517303
!
!
username SCORPION privilege 15 view root secret 5 xxxxxxxx
!
!
ip tcp synwait-time 10
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
ip rcmd rcp-enable
ip rcmd remote-host sdmR84979c1a 192.168.0.15 L84979c1a enable
ip rcmd remote-username sdmR84979c1a
!
!
buffers tune automatic
!
!
!
interface FastEthernet0/0
description {SCORPNET)$ETH-LAN$$FW_INSIDE$
mac-address 000f.23c4.6e80
ip address 192.168.0.50 255.255.255.0
ip access-group 101 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip nbar protocol-discovery
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
ip route-cache flow
speed auto
full-duplex
no mop enabled
!
interface Serial0/0
no ip address
shutdown
no fair-queue
!
interface ATM0/1
no ip address
shutdown
atm restart timer 300
no atm ilmi-keepalive
dsl operating-mode auto
!
interface FastEthernet1/0
description (ATT Uverse)$ETH-WAN$$FW_OUTSIDE$
mac-address 000f.23c4.6e90
ip address 107.219.166.17 255.255.255.248
ip access-group 102 in
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip nbar protocol-discovery
ip flow ingress
ip flow egress
ip nat outside
ip inspect SDM_LOW out
ip ips sdm_ips_rule in
ip virtual-reassembly
ip route-cache flow
speed auto
full-duplex
no cdp enable
no mop enabled
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 107.219.166.22 permanent
!
!
ip http server
ip http access-class 2
ip http secure-server
ip nat inside source list 1 interface FastEthernet1/0 overload
ip nat inside source static tcp 192.168.0.1 20 107.219.166.17 20 extendable
ip nat inside source static tcp 192.168.0.1 21 107.219.166.17 21 extendable
ip nat inside source static tcp 192.168.0.10 25 107.219.166.17 25 extendable
ip nat inside source static tcp 192.168.0.1 80 107.219.166.17 80 extendable
ip nat inside source static udp 192.168.0.11 88 107.219.166.17 88 extendable
ip nat inside source static tcp 192.168.0.1 990 107.219.166.17 990 extendable
ip nat inside source static tcp 192.168.0.11 3074 107.219.166.17 3074 extendable
ip nat inside source static udp 192.168.0.11 3074 107.219.166.17 3074 extendable
ip nat inside source static udp 192.168.0.1 17478 107.219.166.17 17478 extendable
ip nat inside source static tcp 192.168.0.1 50000 107.219.166.17 50000 extendable
ip nat inside source static tcp 192.168.0.1 50001 107.219.166.17 50001 extendable
ip nat inside source static tcp 192.168.0.1 50002 107.219.166.17 50002 extendable
ip nat inside source static tcp 192.168.0.1 50003 107.219.166.17 50003 extendable
ip nat inside source static tcp 192.168.0.1 50004 107.219.166.17 50004 extendable
ip nat inside source static tcp 192.168.0.1 50005 107.219.166.17 50005 extendable
ip nat inside source static tcp 192.168.0.1 55368 107.219.166.17 55368 extendable
ip nat inside source static tcp 192.168.0.15 60817 107.219.166.17 60817 extendable
!
logging source-interface FastEthernet0/0
logging 192.168.0.1
access-list 1 permit 192.168.0.0 0.0.0.255
access-list 23 permit 192.168.0.15
access-list 23 permit 192.168.0.1
access-list 100 remark auto generated by SDM firewall configuration
access-list 100 remark SDM_ACL Category=1
access-list 100 deny ip host 255.255.255.255 any
access-list 100 deny ip 127.0.0.0 0.255.255.255 any
access-list 100 permit ip any any
access-list 101 remark auto generated by SDM firewall configuration
access-list 101 remark SDM_ACL Category=1
access-list 101 deny ip 107.219.166.16 0.0.0.7 any
access-list 101 deny ip host 255.255.255.255 any
access-list 101 deny ip 127.0.0.0 0.255.255.255 any
access-list 101 permit ip any any
access-list 102 remark auto generated by SDM firewall configuration
access-list 102 remark SDM_ACL Category=1
access-list 102 remark DELTA FORCE LAND WORRIOR
access-list 102 permit udp any host 107.219.166.17 eq 17478
access-list 102 remark XBOX
access-list 102 permit udp any host 107.219.166.17 eq 88
access-list 102 permit udp any host 107.219.166.17 eq 3074
access-list 102 permit tcp any host 107.219.166.17 eq 3074
access-list 102 remark WWW
access-list 102 permit tcp any host 107.219.166.17 eq www
access-list 102 remark SMTP
access-list 102 permit tcp any host 107.219.166.17 eq smtp
access-list 102 remark FTP
access-list 102 permit tcp any host 107.219.166.17 eq ftp
access-list 102 permit tcp any host 107.219.166.17 eq ftp-data
access-list 102 permit tcp any host 107.219.166.17 eq ftp-data established
access-list 102 permit tcp any host 107.219.166.17 range 50000 50005
access-list 102 permit tcp any host 107.219.166.17 eq 990
access-list 102 remark uTORRENT
access-list 102 permit tcp any host 107.219.166.17 eq 60817
access-list 102 permit tcp any host 107.219.166.17 eq 55368
access-list 102 remark DNS
access-list 102 permit udp host 192.168.0.1 eq domain host 107.219.166.17
access-list 102 permit udp host 192.168.0.10 eq domain host 107.219.166.17
access-list 102 deny ip 192.168.0.0 0.0.0.255 any
access-list 102 remark ICMP
access-list 102 permit icmp any host 107.219.166.17 echo-reply
access-list 102 permit icmp any host 107.219.166.17 time-exceeded
access-list 102 permit icmp any host 107.219.166.17 unreachable
access-list 102 deny ip 10.0.0.0 0.255.255.255 any
access-list 102 deny ip 172.16.0.0 0.15.255.255 any
access-list 102 deny ip 192.168.0.0 0.0.255.255 any
access-list 102 deny ip 127.0.0.0 0.255.255.255 any
access-list 102 deny ip host 255.255.255.255 any
access-list 102 deny ip host 0.0.0.0 any
access-list 102 deny ip any any log
snmp-server community xxxxx RW
snmp-server chassis-id STINGER
snmp-server host 192.168.0.15 version 2c6 xxxxxxxx
no cdp run
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
!
line con 0
exec-timeout 5 0
login authentication local_auth
transport preferred none
transport output telnet
speed 115200
line aux 0
login authentication local_auth
no exec
transport output telnet
line vty 0 4
access-class 23 in
exec-timeout 20 0
privilege level 15
password 7 xxxxxx
login authentication local_auth
transport preferred none
transport input ssh
!
scheduler allocate 4000 1000
ntp logging
ntp clock-period 17180243
ntp server 192.168.0.1 prefer
!
end
10-29-2013 06:50 PM
5 Mbps is just about right.
Read this: Routing Performance
10-29-2013 09:56 PM
I read it.....but I am just wondering.............
It is normal for a router to "eat" that much throughput.....and
When I was using the router with straight DSL (6Mbps) thru a wic-adsl card I was getting the full 6Mbps
10-30-2013 03:01 AM
Solved it..............
Set memory-size io 10
Got rid of IPS....
Now getting 10-11Mbps.......
10-30-2013 07:40 AM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
I would expect most, if not all, of the performance improvement might have been from removal of IPS.
BTW, you should be careful adjusting IO memory-size. I recall there's a way to "default" it, so it will acquire what it thinks it needs as a minimum during boot.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: