Hi Support people,
I have been trialling IOS IPS on a number of Cisco ISRg2 routers and I have found that after enabling it the CPU jumps to 99% and I see packet drops (ingress) on the interface that IPS is applied.
Has anyone else successfully deployed IOS IPS? If yes what router/s have you used and what did you do to mitigate high CPU usage and packet drops?
Thank you in advance for all of your quick reply’s
Using IOS-IPS is recommended for some very basic use and small deployments only.
As there are limited resources available on the router; using IOS IPS has a direct impact on the speed/throughput of the router and generally not recommended to enable most of signature on it.
We only recommend enabling some very basic signature package on the IOS-IPS for basic packet inspection.
Enabling all the signatures can result in high CPU on the router as well.'
Datasheet
The above guide will be very helpful.
Regards
Sachin