10-28-2015 01:59 AM - edited 03-08-2019 02:28 AM
Hi
I have a DMVPN setup with a hub and spoke sites. I have noticed when I send continuous pings (1000) I am alway getting 99% success rate.
On checking all the tunnel and physical interfaces, I have noticed that on the spokes, I am getting output drops on the tunnel interfaces. I am also seeing drops on the internal facing interface.
Tunnel100 is up, line protocol is up
Hardware is Tunnel
Description: ** DMVPN Tunnel over MPLS **
Internet address is 10.254.1.4/24
MTU 9960 bytes, BW 50000 Kbit/sec, DLY 5000 usec,
reliability 255/255, txload 11/255, rxload 1/255
Encapsulation TUNNEL, loopback not set
Keepalive set (10 sec), retries 3
Tunnel linestate evaluation up
Tunnel source 213.81.6.233 (GigabitEthernet0/0/0)
Tunnel Subblocks:
src-track:
Tunnel100 source tracking subblock associated with GigabitEthernet0/0/0
Set of tunnels with source GigabitEthernet0/0/0, 1 member (includes iterators), on interface <OK>
Tunnel protocol/transport multi-GRE/IP
Key 0x65, sequencing disabled
Checksumming of packets disabled
Tunnel TTL 255, Fast tunneling enabled
Tunnel transport MTU 1460 bytes
Tunnel transmit bandwidth 8000 (kbps)
Tunnel receive bandwidth 8000 (kbps)
Tunnel protection via IPSec (profile "DMVPN-PROFILE1")
Last input 00:00:10, output never, output hang never
Last clearing of "show interface" counters 1w5d
Input queue: 0/375/0/0 (size/max/drops/flushes); Total output drops: 647117
Queueing strategy: fifo
Output queue: 0/0 (size/max)
5 minute input rate 22000 bits/sec, 23 packets/sec
5 minute output rate 2204000 bits/sec, 510 packets/sec
84355670 packets input, 18950853760 bytes, 0 no buffer
Received 0 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
109761781 packets output, 25180793557 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
Would these drops expplain why I only seem to achieve 99% ping success. Is there anything I can change on the interface. Currently the traffic load is not major as we only have a few test users on this network.
Thnaks
11-06-2015 04:01 AM
To be honest I don't consider 1 packet loss on 1000 to be a big issue however you may conside increasing queue size on the interface.
11-09-2015 03:28 AM
Thanks for the response, After further investigation, I spoke to the ISP who made changes at their end and fixed the issue. Apparently one of their switches in the path was dropping packets for all customers.
11-09-2015 03:38 AM
BTW, that may explain a ping improvement, but drops inside their cloud shouldn't show as drops on your interfaces.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide