04-29-2013 02:38 AM - edited 03-04-2019 07:45 PM
Good mornign all,
I have a Cisco 2911 router which is running the c2900-universallk9-mz.SPA.153-1.T version
On this router, a GRE without IPSEC tunnel is configured and works fine. For management purposes I have to create an IPSEC tunnel which terminate on this router as well.
So this router shall to concentrate 2 differents tunnels. A existing GRE and a future IPSEC.
I have already configured the cryptomap, ACLs on the router. BUT when I apply the cryptomap to the external interface, the performance of the flows going to the GRE tunnel are very degraded.
Any ideas?
Thank you very much for your help.
regards,
04-29-2013 05:14 AM
Could you send us "show proccess cpu" out command?. Could it be a CPU problem?.
Regards.
04-29-2013 06:13 AM
Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
There's going to be some performance degradation, due to encryption. However, often with tunnels, performance will degrade much if there's packet fragmentation.
Have you seen: http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: