cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

ARE USING CRYPTO MODULE, OR ON-BOARD MODULE?

Hi everyone.

I have a 3845 cisco router using crypto maps to establish crypto sessions with almost one hundred routers, the last 2 days the crypto sesssions are falling down and the process cpu increase, the error messagess is this one:

100                                                  **        
90                                                 ##*        
80                                                 ##*        
70                                                 ###        
60                                                 ### *      
50                                                 ###**      
40  *** ***   * #***  * #*****  *   ***            ######***#*#
30 ############################################****############
20 ############################################################
10 ############################################################
   0....5....1....1....2....2....3....3....4....4....5....5....
             0    5    0    5    0    5    0    5    0    5  

*Jan 27 10:46:21: %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED: Pak spent too much time in the IKE input queues

XXXX#sh clock
*11:37:48.378 COL Thu Jan 27 2011

    3434444464333433333333333333333333333333222999944433343333
    9181541171976179454336561454566736492183621997702276529879
100                                            *##*            
90                                            *##*            
80                                            *###            
70         *                                  *###            
60         *                                  *###            
50     *   *                                  *###            
40 *#########*****# *   ***  * **** * *  *    #######***##**###
30 ########################################*  #################
20 ############################################################
10 ############################################################
   0....5....1....1....2....2....3....3....4....4....5....5....
             0    5    0    5    0    5    0    5    0    5   
               CPU% per minute (last 60 minutes)


*Jan 28 10:59:36: %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED: Pak spent too much time in the IKE input queues

XXX#sh clock
*11:45:09.299 COL Fri Jan 28 2011

I look at cisco web and the explanation is this one:

If the IKE process is under heavy load, incoming IKE packets may spend too much time in the IKE input queue which will result in the generation of a error level (severity 3) Syslog message. The Syslog message is %CRYPTO-3-IKE_PAK_IN_Q_TIME_LIMIT_EXCEED.

The router uses VPN module, I dont know if are really using the vpn module, How Can i look It?

How Can I fix it my problem?

Cisco IOS:flash:c3845-advipservicesk9-mz.124-9.T7.bin

Who Me Too'd this topic