cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
612
Views
0
Helpful
3
Replies

High CPU Due to NAT

witani
Level 1
Level 1

Dears,

I have a 7206 VXR NPE-G2 running in an ISP at 40% CPU in peak time.

I applied NAT with overload based on the ACL below. After that, CPU started to reached 90 % in peak time. 

Is that expected or I am missing something ?

Extended IP access list MATCH_VOIP

    30 permit udp any any eq 5070

    35 permit tcp any any eq 5070

    40 permit udp any any eq 5060

    45 permit tcp any any eq 5060

    50 permit udp any any eq 1720

    55 permit tcp any any eq 1720

    60 permit udp any any eq 1731

    65 permit tcp any any eq 1731

ip nat inside source route-map NAT_VOIP_GLOBAL pool VOIP_GLOBAL overload

Regards,

3 Replies 3

Marc Faggion
Cisco Employee
Cisco Employee

The 7200 NPE-G2 is a software switched router so any additional features enabled on the packet path increases the amount of CPU used. As to if this is reasonable or not, I suspect there are documents on the cisco site indicating the expected CPU utilization for a given featureset.offered load combination.

I suspect there are documents on the cisco site indicating the expected CPU utilization for a given featureset.offered load combinati

That is not the case, there are no such documents available, and everything is pretty much based on individual expereince and common sense.

paolo bevilacqua
Hall of Fame
Hall of Fame

witani wrote:

Dears,

I have a 7206 VXR NPE-G2 running in an ISP at 40% CPU in peak time.

I applied NAT with overload based on the ACL below. After that, CPU started to reached 90 % in peak time. 

Is that expected or I am missing something ?

Extended IP access list MATCH_VOIP

    30 permit udp any any eq 5070

    35 permit tcp any any eq 5070

    40 permit udp any any eq 5060

    45 permit tcp any any eq 5060

    50 permit udp any any eq 1720

    55 permit tcp any any eq 1720

    60 permit udp any any eq 1731

    65 permit tcp any any eq 1731

ip nat inside source route-map NAT_VOIP_GLOBAL pool VOIP_GLOBAL overload

Try compiled (turbo) ACL:

http://www.cisco.com/en/US/products/sw/iosswrel/ps1829/products_feature_guide09186a00800881a7.html

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card