Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

High CPU Due to NAT

Dears,

I have a 7206 VXR NPE-G2 running in an ISP at 40% CPU in peak time.

I applied NAT with overload based on the ACL below. After that, CPU started to reached 90 % in peak time. 

Is that expected or I am missing something ?

Extended IP access list MATCH_VOIP

    30 permit udp any any eq 5070

    35 permit tcp any any eq 5070

    40 permit udp any any eq 5060

    45 permit tcp any any eq 5060

    50 permit udp any any eq 1720

    55 permit tcp any any eq 1720

    60 permit udp any any eq 1731

    65 permit tcp any any eq 1731

ip nat inside source route-map NAT_VOIP_GLOBAL pool VOIP_GLOBAL overload

Regards,

3 REPLIES
Cisco Employee

Re: High CPU Due to NAT

The 7200 NPE-G2 is a software switched router so any additional features enabled on the packet path increases the amount of CPU used. As to if this is reasonable or not, I suspect there are documents on the cisco site indicating the expected CPU utilization for a given featureset.offered load combination.

Hall of Fame Super Gold

Re: High CPU Due to NAT

I suspect there are documents on the cisco site indicating the expected CPU utilization for a given featureset.offered load combinati

That is not the case, there are no such documents available, and everything is pretty much based on individual expereince and common sense.

Hall of Fame Super Gold

Re: High CPU Due to NAT

witani wrote:

Dears,

I have a 7206 VXR NPE-G2 running in an ISP at 40% CPU in peak time.

I applied NAT with overload based on the ACL below. After that, CPU started to reached 90 % in peak time. 

Is that expected or I am missing something ?

Extended IP access list MATCH_VOIP

    30 permit udp any any eq 5070

    35 permit tcp any any eq 5070

    40 permit udp any any eq 5060

    45 permit tcp any any eq 5060

    50 permit udp any any eq 1720

    55 permit tcp any any eq 1720

    60 permit udp any any eq 1731

    65 permit tcp any any eq 1731

ip nat inside source route-map NAT_VOIP_GLOBAL pool VOIP_GLOBAL overload

Try compiled (turbo) ACL:

http://www.cisco.com/en/US/products/sw/iosswrel/ps1829/products_feature_guide09186a00800881a7.html

434
Views
0
Helpful
3
Replies
CreatePlease to create content