Hi to all.
We have the customer that have some brunches. Each of them connected to their ISP. Central office connected to us. All branches connect to central office via VPN (IPsec). So the issue is in receiving fragmented packets from their ISP. With enabled ip virtual reassembly - all customer traffic transmitt well, but buffer overflow and there is a lot of overlap fragments (%IP_VFR-3-OVERLAP_FRAGMENTS:), and it's affected to cpu utilization (cpu loads to 99%). I have disabled ip virtual reassembly by issuing ip virtual-reassembly in drop-fragments in command on our uplink interface, cpu utilization is normal, but customer traffic in their tunnel works incorrectly (some packets losts). Can anybody help me with this problem?