06-15-2011 04:37 AM - edited 02-21-2020 05:24 PM
hi all,
I just installed a new ISR G2 3925e (spe200 integrated) in a VPN environment
it works well but I lost latency (it adds around 8-10 ms in the VPN) because of "
IPsec packet batching" :
Queues multiple packets at the interrupt service routine level after being processed by crypto engine Reduces interrupt context switching by allowing one crypto interrupt for multiple crypto packets
It's not very good specaly if you tunnel ToIP and/or video streams
I'm trying to find a solution how to disable it without impact other things or is there something planned soon to improve it
fyi I use IOS c3900e-universalk9-mz.SPA.151-4.M.bin
regards
Niko
06-15-2011 05:40 AM
Hi,
You can try "service internal" and then "no crypto batch allowed" from the configuration mode.
Hope this helps.
Thanks,
Wen
06-15-2011 06:24 AM
it doesn't work, I already tried it
I'm in discussion with TAC about it :
router(config)#service int
router(config)#service internal
router(config)#no cry
router(config)#no crypto ba
router(config)#no crypto batch allowed
^
% Invalid input detected at '^' marker.
Niko
PS : fyo, when I enter "service internal", router adds "ip inspect WAAS flash...", so I need to do "no service internal" to remove it ; very strange
06-26-2011 12:46 AM
finaly I found, it is a bug in IOS I use
so if that can help
bug is =>
CSCto34196
fixed in 15.1(4)M1
Regards
Nicolas
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide