cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
719
Views
0
Helpful
2
Replies

Performance degraded with GRE and IPSEC

Isidore Moreno
Level 1
Level 1

Good mornign all,

I have a Cisco 2911 router which is running the c2900-universallk9-mz.SPA.153-1.T version

On this router, a GRE without IPSEC tunnel is configured and works fine. For management purposes I have to create an IPSEC tunnel which terminate on this router as well.

So this router shall to concentrate 2 differents tunnels. A existing GRE and a future IPSEC.

I have already configured the cryptomap, ACLs on the router. BUT when I apply the cryptomap to the external interface, the performance of the flows going to the GRE tunnel are very degraded.

Any ideas?

Thank you very much for your help.

regards,

2 Replies 2

antonio.guirado
Level 3
Level 3

Could you send us "show proccess cpu" out command?. Could it be a CPU problem?.

Regards.

Joseph W. Doherty
Hall of Fame
Hall of Fame

Disclaimer

The  Author of this posting offers the information contained within this  posting without consideration and with the reader's understanding that  there's no implied or expressed suitability or fitness for any purpose.  Information provided is for informational purposes only and should not  be construed as rendering professional advice of any kind. Usage of this  posting's information is solely at reader's own risk.

Liability Disclaimer

In  no event shall Author be liable for any damages whatsoever (including,  without limitation, damages for loss of use, data or profit) arising out  of the use or inability to use the posting's information even if Author  has been advised of the possibility of such damage.

Posting

There's going to be some performance degradation, due to encryption.  However, often with tunnels, performance will degrade much if there's packet fragmentation.

Have you seen: http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml?

Review Cisco Networking products for a $25 gift card