cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
744
Views
5
Helpful
2
Replies

IPSec SA Congestion

zekebashi
Level 4
Level 4

Hello,

 

We've been having an issue with one of the IPSec Tunnels where the tunnel would stay up but becomes congested which causes significant traffic delays and latency. The only way to resolve the issue is if we reset the tunnel on one of the ends(i.e. Site A). I've been trying to search for information to explain why the tunnel would become congested, what commands to use to diagnose the congestion issue, and how to resolve such issues. 

 

I appreciate the assistance.

 

Best, ~sK

 

 

2 Replies 2

Hi,
When you say congested that would imply that a lot of traffic is going over the VPN tunnel, you probably need to increase the bandwidth or use QoS to shape the traffic. You can use netflow in order to identify the top talkers (source/destination) and define QoS policies from there.

Assuming it's you are using an ASA the command "show local-host detail" would give use some information on the hosts and the number of connections, traffic etc.

HTH

Thanks for your input and suggestions. Yes, we're using ASAs. The command you provided is very helpful.

 

Much appreciated.

 

Best, ~zK

Review Cisco Networking products for a $25 gift card