01-28-2011 09:20 AM
Hi everyone.
I have a 3845 cisco router using crypto maps to establish crypto sessions with almost one hundred routers, the last 2 days the crypto sesssions are falling down and the process cpu increase, the error messagess is this one:
100 **
90 ##*
80 ##*
70 ###
60 ### *
50 ###**
40 *** *** * #*** * #***** * *** ######***#*#
30 ############################################****############
20 ############################################################
10 ############################################################
0....5....1....1....2....2....3....3....4....4....5....5....
0 5 0 5 0 5 0 5 0 5
*Jan 27 10:46:21: %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED: Pak spent too much time in the IKE input queues
XXXX#sh clock
*11:37:48.378 COL Thu Jan 27 2011
3434444464333433333333333333333333333333222999944433343333
9181541171976179454336561454566736492183621997702276529879
100 *##*
90 *##*
80 *###
70 * *###
60 * *###
50 * * *###
40 *#########*****# * *** * **** * * * #######***##**###
30 ########################################* #################
20 ############################################################
10 ############################################################
0....5....1....1....2....2....3....3....4....4....5....5....
0 5 0 5 0 5 0 5 0 5
CPU% per minute (last 60 minutes)
*Jan 28 10:59:36: %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED: Pak spent too much time in the IKE input queues
XXX#sh clock
*11:45:09.299 COL Fri Jan 28 2011
I look at cisco web and the explanation is this one:
If the IKE process is under heavy load, incoming IKE packets may spend too much time in the IKE input queue which will result in the generation of a error level (severity 3) Syslog message. The Syslog message is %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED.
The router uses VPN module, I dont know if are really using the vpn module, How Can i look It?
How Can I fix it my problem?
Cisco IOS:flash:c3845-advipservicesk9-mz.124-9.T7.bin