cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
899
Views
5
Helpful
5
Replies

ASR1000-X Encryption Throughput

hotpackets
Level 1
Level 1

I'm looking at an ASR1K-X with an ESP40. Datasheets shows up to 12Gbps encrypted aggregate throughput.

If I exceed those numbers, is there a command that would show drops that occurred due to hitting encryption/decryption limits?

Is it QOS aware? With encryption happening before queuing and scheduling, would it still encrypt/decrypt PQ1 and PQ2 packets first?

1 Accepted Solution

Accepted Solutions

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

   This is the command you're looking for, as you're looking for data-plane drops: "show platform hardware qfp statistics drop". Take  look at this document for further reference:

 

https://community.cisco.com/t5/security-documents/troubleshooting-vpn-issues-on-asr-where-to-start/ta-p/3113897

 

Regards,
Cristian Matei.

 

View solution in original post

5 Replies 5

Joseph W. Doherty
Hall of Fame
Hall of Fame
"With encryption happening before queuing and scheduling, would it still encrypt/decrypt PQ1 and PQ2 packets first?"

I don't know for sure, but doubt it would. I suspect encryption/decryption is FIFO.

That's my suspicion, but I wanted to see if anyone knew for sure.

I received confirmation from a Cisco engineer that the crypto module will indiscriminately drop traffic when its capacity is exceeded.

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

   This is the command you're looking for, as you're looking for data-plane drops: "show platform hardware qfp statistics drop". Take  look at this document for further reference:

 

https://community.cisco.com/t5/security-documents/troubleshooting-vpn-issues-on-asr-where-to-start/ta-p/3113897

 

Regards,
Cristian Matei.

 

Thanks! That document appears to have what I'm looking for.
Review Cisco Networking for a $25 gift card