07-28-2005 09:28 AM - edited 03-03-2019 10:09 AM
Hi
We have an IPSec over GRE tunnel from Site A to Site Z, travelling through a big cloud from A->B- --- to --- Y->SiteZ.
The protected networks in SiteA are having a lot of latency accessing the intended servers in SiteZ through the encryption path.
The tunnel Util shows 255/255 both Tx and Rx.
But there are no output drops whatsoever.
My question of concern is,
<1>On what basis does this utilization get calculated ?
<2>Also, the Bandwidth statement on the tunnel interface is only for the routing protocol as I understand it.
Thanks in advance :0)
Arav
===================
Tunnel13 is up, line protocol is up
Hardware is Tunnel
Description: Encryption tunnel to SITE_Z
Interface is unnumbered. Using address of Loopback1 (32.29.12.2)
MTU 1514 bytes, BW 9 Kbit, DLY 500000 usec,
reliability 255/255, txload 255/255, rxload 255/255
Encapsulation TUNNEL, loopback not set
Keepalive not set
Tunnel source 32.29.12.2 (Loopback1), destination 53.35.8.7
Tunnel protocol/transport GRE/IP, key disabled, sequencing disabled
Tunnel TTL 255
Checksumming of packets disabled, fast tunneling enabled
Tunnel transmit bandwidth 8000 (kbps)
Tunnel receive bandwidth 8000 (kbps)
Last input 00:24:11, output 04:25:56, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/0 (size/max)
5 minute input rate 24000 bits/sec, 37 packets/sec
5 minute output rate 24000 bits/sec, 35 packets/sec
6347636 packets input, 528273410 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
8656084 packets output, 636266189 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 output buffer failures, 0 output buffers swapped out
interface Tunnel13
description Encryption tunnel to SITE_Z
ip unnumbered Loopback1
ip mtu 1390
ip route-cache flow
ip tcp adjust-mss 1360
tunnel source Loopback1
tunnel destination 53.35.8.7
crypto map SITE_A_to_Z
==============
07-28-2005 10:19 AM
The load is actually calculated from the "bandwidth" command.
So unless this is really a 9K circuit that is probably why your showing 100% utilization.
07-28-2005 10:29 AM
what type of hardware are you using. I have had problems where the limitations of the routers were causing the latency?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide