cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
525
Views
4
Helpful
2
Replies

ACL lookup process and the sh proc cpu command

bridgmountm
Level 1
Level 1

I have a router showing heavy CPU utilisation. The actual load on the router is significant but the output of the show proc cpu command doesn't tie up with the totabl CPU load. This router does however have massive ACL's configured. The question is, "is the ACL lookup process shown in the IP Input process or is it a background one and not listed ??"

Thanks

2 Replies 2

daniel.bowen
Level 1
Level 1

If you add up the sum of the individual processes on the show proc cpu command, and then subtract that from the total CPU utilization, the remaining number is traffic. Traffic does not show up in the breakdown of the processes.

ACL's I believe fall under IP input.

Hope this helps,

Daniel,

PS - How big are the ACL's and what router are you using?

The ACLs are done per interface but intotal I would say there are about 2000 lines. They aren't optimised and have a lot of redundancies in. The routers are 3640's

Thanks for you help

Murray

Review Cisco Networking for a $25 gift card