cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2209
Views
16
Helpful
28
Replies

Latency issue with 4431

ELLE22
Level 1
Level 1

Hello everyone, please need your help.

we had an old 2921 router, everything worked fine, we had 2 DMVPN tunnels via ipsec and isakmp.

we had to change the router 2921 to isr 4331, and keep the same configuration, after changing to 4431, the employees noticed a big latency problem, we tried to troubleshoot, we had the same configuration as 2921 the only difference was the isakmp key , on the new 4331 the key was encrypted, but in the other routers and the old one the key was not encrypted.

According to  your experience, can a bad isakmp  key cause latency?

thank you in advance . 

28 Replies 28

khorram1998
Level 1
Level 1

It is unlikely that an encryption key would cause significant latency on its own. However, there could be other factors that are contributing to the latency issue. It would be beneficial to investigate other potential causes such as the network topology, routing, and QoS configurations, as well as the overall health of the network. Additionally, it would be a good idea to check if there is any difference in the performance of the new ISR 4331 router compared to the old 2921 router, such as CPU and memory usage, to ensure that the new router is able to handle the traffic load.

Please rate this and mark as solution/answer, if this resolved your issue
All the best,
AK

Thank you for you response ,  the configuration is the same as 2921 , Qos ,too . 

we have mpls (20 mbps ) , when we did the speed test from a desktop with the 2921 we got 8mbps , 10 mbps down and 15 mbps up , but with the new router we got 0.12 mbps , 3mbps down and 17 mbps up .

4331 throughput  is 100 mbps 

Joseph W. Doherty
Hall of Fame
Hall of Fame

What throughput license, if not using the Boost license, is your 4331 running?

Interestingly, Cisco documents a 2921 can (actual RFC-2544 test) hit 3.5 Gbps throughput (in an ideal setup), but notes the 4331, with Boost license, can "over 2 Gbps".  I.e. perhaps the 2921 has more raw performance than a 4331 (personally, I doubt it does).  If so, this might account for a slow down.

Oh, and as even the 4331 Performance license limits throughput to 300 Mbps, that might really add latency (as the license shapes transit traffic's bandwidth) vs. your old 2921 (which Cisco documents of providing up to 72 Mbps, IMIX traffic, across IPSec, not exceeding 75% CPU load).

BTW, Miercom testing often shows many ISR 4Ks struggling with IPSec traffic around their "Performance" level of throughput.  I.e. even with a Boost license, an ISR 4K might be unable, again with IPSec traffic, to much exceed their "Performance" level of throughtput.

Oh, BTW, is issue with 4331 or 4431 or both?  The latter is a more "powerful" router than the former, and it (4431) should be able, I believe, outperform a 2921.

just 4331

just 4331 in 8 locations now , the strange thing we have 4 location with 4331 and they re working properly , but the 8 others no , we checked the config  , the license everything is same 

ip mtu 1400 <<- this your config under tunnel 

the 4 sites with issue, please ping with size 1350-1400 df-set 
if the ISP is different then the issue can be MTU ISP accept.  

yes ip mtu 1400 under tunnels 

reduce the MTU and check.

i tried to reduce the mtu and still same issue

do you ping using set df-bit ?

I believe (???) there's a command to determine if the license cap is, in fact, limiting throughput.  Unfortunately, if there is such a command, I don't recall what it is.

If command exists, likely worthwhile to try on your problematic (in performance) routers.

the throughput of the routers impacted  is 100 mbps , and we have just  20 mbps via mpls  and 4 other 4331 are working fine with the same throughput , same config same everything

ELLE22
Level 1
Level 1

another update , i had the ISP tech tested our MPLS circuit and our router , everything was good , but still connection slow with 4331 and normal with 2921 . i plugged my laptop in the Lan interface of the 4331 and it was working fine , i got the normal speed ... in the Lan side we have aruba switch 2930 .the aruba is working fine with 2921 router . tried to change the interface speed on aruba but still slow connection  

Any Idea ? 

Thank you in advance 

Review Cisco Networking for a $25 gift card