cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
247
Views
0
Helpful
1
Replies

NAT limitations with 3640

bala.kcs
Level 1
Level 1

Hi,

I have a 3620 working on overload NAT function, which does NAT roughtly 125 inside IPs to the public IP.. The problem I face is the router CPU utilisation is accumulating periodically and I have to do a "clear ip nat translations" to bring my CPU utilisation to normal. Once I do clear ip nat .. CPU utl drops to 5% or less. Users on the LAN are also feeling the difference as the NAT table is cleared. Iam also using NAT translation time out for TCP as 10seconds, so the NAT table clears automatically when the traffic stops. I have enabled CEF also which has shown slight improvements. Is there any limitations on the number of translations the router can do ?... Can someone also suggest is there any IOS bugs relating to this.

The IOS router uses is : 12.1.3a

Feature set is : IP plus

regards,

KCS Balaji

email : kcsbala@vsnl.net

1 Reply 1

Hello,

125 entries shoud not be a problem. You might want to check out this link:

http://www.cisco.com/en/US/partner/products/sw/iosswrel/ps1828/products_tech_note09186a00800a70f2.shtml

It is for IOS 12.0, but should apply to 12.1, too.

Might be a longshot, but here is a link to an article which describes high CPU utilization due to machines infected with Code Red:

http://www.cisco.com/en/US/partner/products/sw/iosswrel/ps1831/products_tech_note09186a00800a73e9.shtml

Regards,

Georg