Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Pounding an ISR

Reply
Thread Tools

Pounding an ISR

 
 
amattina@layer8group.com
Guest
Posts: n/a
 
      11-06-2006
This is somewhat of an update/continuation of the following thread:

http://groups.google.com/group/comp....51510dbb485122

Basic rundown is that the 'ip inspect' functionality on a 2811 ISR
(12.4) starts at 500/400 connections before it starts dropping and
resetting communication. I upped this 500/400 default value to
2000/1900 and everything was fixed and worked for about 3 months. I get
another call today with the same symptoms and sure enough:

----
ISR-001#show ip inspect stat
Packet inspection statistics [process switch:fast switch]
tcp packets: [24753726:469573947]
udp packets: [119628550:270177156]
ftp packets: [449452:0]
Interfaces configured for inspection 1
Session creations since subsystem startup or last reset 25632398
Current session counts (estab/half-open/terminating) [235:3:0]
Maxever session counts (estab/half-open/terminating) [2347:299:62]
Last session created 00:00:00
Last statistic reset never
Last session creation rate 4455
Last half-open session total 3
Half-open session count or session creation rate exceeded
----

'Last session creation rate 4455' is the key here. So I bump the limit
up to 5000/4900. CPU on this device is between 25-35% util. throughout
the day on a 4mbit uplink. Question is, (and for any discussion as
well) how much will this thing take? I'll keep on upping the
connection threshold until the CPU gets high enough to upgrade the
device but any other ideas would be appreciated. I know 'ip inspect' is
supposed to make processing faster by not parsing through the ACLs for
every connection but does this become innefficient at any point?

Thanks for your thoughts!

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ISR (interrupt service routine) code in isr.c Eirik Midttun C Programming 2 02-08-2007 03:52 AM
ISR 1801W & wireless workstations Mr Corbett Cisco 0 10-26-2005 12:34 PM
ISR - VPN Client IP and Subnet mask no DNS Mr Corbett Cisco 0 10-13-2005 11:10 AM
How to setup FXO/FXS Cards with ISR Routers? newbies Cisco 1 07-22-2005 04:36 PM
Command line on ISR routers... (2800...) olivier.martin@gmail.com Cisco 2 07-07-2005 01:00 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57