1841 na łączu 20/8, obciążenie i błędy na interfejsie WAN

Wszystkie rozmowy związane z problemem z hardwarem, supportowanymi funkcjonalnościami, wydajnością urządzeń itp.
Wiadomość
Autor
MarcelLee
wannabe
wannabe
Posty: 75
Rejestracja: 26 wrz 2005, 21:44
Lokalizacja: Sopot

1841 na łączu 20/8, obciążenie i błędy na interfejsie WAN

#1

#1 Post autor: MarcelLee »

Cześć,

Uruchamiam w małym oddziale 1841, który póki co jedyne składa VPN do centrali żeby mieć DNS z HQ i to tylko dla wewnętrznej domeny (AD DS), resztę puszcza bezpośrednio do Internetu.
Łącze to 20mbps download 8mbps upload z lokalnej osiedlówki po radiu, ja dostaje Ethernet, później jest jakaś "czarna skrzynka" i antena na dachu. W moim LANie kilkunastu użytkowników.

Ruch to głownie: HTTP(S), FTP, DNS.
Wykorzystywane funkcjonalności:
DHCP
NAT
DNS forwarder
CBAC
VPN S2S do ASA w HQ
Kilka prostych ACL

Kod: Zaznacz cały

Cisco 1841 (revision 4.1) with 239616K/22528K bytes of memory.
Processor board ID .....
2 FastEthernet interfaces
1 Virtual Private Network (VPN) Module
DRAM configuration is 64 bits wide with parity disabled.
191K bytes of NVRAM.
62720K bytes of ATA CompactFlash (Read/Write)
Ciągle zastawiam się czy przyczyną obciążenia są błędy na interfejsie, czy może to właśnie obciążenie powoduje błędy na interfejsie?
Nie wiem jak to ugryźć, będę wdzięczny za jakieś sugestie, jak dalej ugryźć temat.

Poniżej trochę danych:

Kod: Zaznacz cały

R-002#sh proc cpu history

R-002   09:58:18 AM Tuesday Dec 30 2014 UTC




      12222222222     22222555558888887777999997777777777666667777
      200000444448888811111333334444449999000003333311111000007777
  100
   90                                     *****
   80                           ***************               ****
   70                           *************************     ****
   60                           **********************************
   50                      ***************************************
   40                      ***************************************
   30                      ***************************************
   20  **********     ********************************************
   10 ************************************************************
     0....5....1....1....2....2....3....3....4....4....5....5....6
               0    5    0    5    0    5    0    5    0    5    0
               CPU% per second (last 60 seconds)




      897592 35122421324338535441776778998889988888877876688888888
      829208780834626216033285184553862990630016719006192455728247
  100                                  **
   90 **  *                            ** * ** ** *       *** *  *
   80 *** *               *      ** ***##*#*##*####* ***  **#*##*#
   70 #** *               *      ** #*#############**###  ########
   60 #** *               *  *   *#*##############################
   50 ##***   *   *    *  ** * * *################################
   40 ###**  **   *    *  ****** *################################
   30 ###*#* **   *  * *######## *################################
   20 #####* ##***#****######### *################################
   10 ##########################*#################################
     0....5....1....1....2....2....3....3....4....4....5....5....6
               0    5    0    5    0    5    0    5    0    5    0
               CPU% per minute (last 60 minutes)
              * = maximum CPU%   # = average CPU%




      973534343765947849999999884455557575444544425774545548443453454444353526
      584378886590940298999692225001169203668360368067290258178118826416741247
  100 *           *    ******
   90 *           *    *******                             *
   80 **       *  *  * *********      *             *      *
   70 **       ** * ** **#******      * *          **      *                 *
   60 #*       ** * ** *###*****     ** *         ***      *                 *
   50 #* * * * **** ****###*#**** *************   ********** *  * ***  * * * *
   40 #* ***************###*#******************** ************************ * *
   30 ##****************###*#*********************************************** *
   20 ##***************########***********************************************
   10 ##***************#########******#***************************************
     0....5....1....1....2....2....3....3....4....4....5....5....6....6....7..
               0    5    0    5    0    5    0    5    0    5    0    5    0
                   CPU% per hour (last 72 hours)
                  * = maximum CPU%   # = average CPU%


R-002#
niepokoją mnie też throttles, input errors, ignored.
unknown protocol to w większośći CDP jakie rozsyłane jest przez urządzenia operatora.

Kod: Zaznacz cały

R-002#sh int fa 0/0
FastEthernet0/0 is up, line protocol is up
  Hardware is Gt96k FE, address is ..... (bia .....)
  Description: OUTSIDE 25/8
  Internet address is CCC.CCC.CCC.181/24
  MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
     reliability 255/255, txload 1/255, rxload 10/255
  Encapsulation ARPA, loopback not set
  Keepalive set (10 sec)
  Full-duplex, 100Mb/s, 100BaseTX/FX
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input 00:00:00, output 00:00:00, output hang never
  Last clearing of "show interface" counters 1w4d
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 4181000 bits/sec, 381 packets/sec
  5 minute output rate 507000 bits/sec, 225 packets/sec
     129736521 packets input, 2833127475 bytes
     Received 3393804 broadcasts (0 IP multicasts)
     0 runts, 0 giants, 134 throttles
     7829 input errors, 0 CRC, 0 frame, 1 overrun, 7827 ignored
     0 watchdog
     0 input packets with dribble condition detected
     70298491 packets output, 1778943957 bytes, 0 underruns
     0 output errors, 0 collisions, 0 interface resets
     526959 unknown protocol drops
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier
     0 output buffer failures, 0 output buffers swapped out
R-002#

Kod: Zaznacz cały

R-002#sh run
Building configuration...

Current configuration : 6716 bytes
!
! Last configuration change at 09:20:46 UTC Tue Dec 30 2014 by .....
version 15.1
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname R-002
!
boot-start-marker
boot-end-marker
!
!
logging buffered 4096
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
!
!
!
!
aaa session-id common
!
dot11 syslog
ip source-route
!
!
no ip dhcp use vrf connected
ip dhcp excluded-address XXX.XXX.10.116
ip dhcp excluded-address XXX.XXX.10.62
ip dhcp excluded-address XXX.XXX.10.100 XXX.XXX.10.149
ip dhcp excluded-address XXX.XXX.10.201 XXX.XXX.10.202
ip dhcp excluded-address XXX.XXX.10.50 XXX.XXX.10.51
ip dhcp excluded-address XXX.XXX.10.149 XXX.XXX.10.254
ip dhcp excluded-address XXX.XXX.10.14
!
ip dhcp pool DHCP-POOL-LAN
 network XXX.XXX.10.0 255.255.255.0
 dns-server XXX.XXX.10.254
 default-router XXX.XXX.10.254
 lease 0 12
!
!
!
ip cef
ip inspect name CBAC-FA0/1-IN tcp
ip inspect name CBAC-FA0/1-IN udp
ip inspect name CBAC-FA0/1-IN dns
ip inspect name CBAC-FA0/1-IN ftp
ip inspect name CBAC-FA0/1-IN ntp
ip inspect name CBAC-FA0/1-IN imap
ip inspect name CBAC-FA0/1-IN imap3
ip inspect name CBAC-FA0/1-IN imaps
ip inspect name CBAC-FA0/1-IN pop3
ip inspect name CBAC-FA0/1-IN pop3s
ip inspect name CBAC-FA0/1-IN icmp
ip inspect name CBAC-FA0/1-IN ftps
ip inspect name CBAC-FA0/1-IN http
ip inspect name CBAC-FA0/1-IN https
ip inspect name CBAC-FA0/1-IN ssh
ip inspect name CBAC-FA0/0-OUT tcp router-traffic
ip inspect name CBAC-FA0/0-OUT udp router-traffic
!
multilink bundle-name authenticated
!
crypto pki token default removal timeout 0
!
crypto pki trustpoint .....
!
!
crypto pki certificate chain .....
!
!
license udi pid CISCO1841 sn .....
license accept end user agreement
archive
 log config
  hidekeys
username .....
!
redundancy
!
!
ip ssh source-interface FastEthernet0/1
!
!
crypto isakmp policy 10
 encr 3des
 authentication pre-share
 group 2
crypto isakmp key ..... address AAA.AAA.AAA.30 no-xauth
!
!
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
!
crypto map CM-OUTSIDE 10 ipsec-isakmp
 set peer AAA.AAA.AAA.30
 set ip access-group ACL-VPN-S2S-R003-FILTER-IN in
 set security-association lifetime kilobytes 1048576
 set security-association lifetime seconds 28800
 set transform-set ESP-3DES-SHA
 set pfs group2
 match address ACL-VPN-S2S-R003
 qos pre-classify
!
!
!
!
!
interface FastEthernet0/0
 description OUTSIDE 25/8
 mac-address .....
 ip address dhcp
 ip access-group ACL-ACG-FA0/0-IN in
 ip inspect CBAC-FA0/0-OUT out
 ip nat outside
 ip virtual-reassembly in
 duplex auto
 speed auto
 no cdp enable
 crypto map CM-OUTSIDE
!
interface FastEthernet0/1
 description INSIDE
 ip address XXX.XXX.10.254 255.255.255.0
 ip access-group ACL-ACG-FA0/1-IN in
 ip inspect CBAC-FA0/1-IN in
 ip nat inside
 ip virtual-reassembly in
 duplex auto
 speed auto
!
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
!
!
ip dns view default
 dns forwarder 8.8.8.8
 dns forwarder 8.8.4.4
ip dns server
no ip nat service sip udp port 5060
ip nat inside source list ACL-NAT-INSIDE interface FastEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 FastEthernet0/0 dhcp
!
ip access-list extended ACL-ACG-FA0/0-IN
 permit udp any eq bootps any eq bootpc
 deny   ip 10.0.0.0 0.255.255.255 any
 deny   ip 172.16.0.0 0.15.255.255 any
 deny   ip 192.168.0.0 0.0.255.255 any
 deny   ip any host 255.255.255.255
 deny   ip any host CCC.CCC.CCC.255
 permit ip host AAA.AAA.AAA.30 any
 permit ip BBB.BBB.BBB.0 0.0.0.255 any
 deny   ip any any log
ip access-list extended ACL-ACG-FA0/1-IN
 permit udp any eq bootpc any eq bootps
 permit ip XXX.XXX.10.0 0.0.0.255 YYY.YYY.5.0 0.0.0.255
 deny   ip any YYY.YYY.5.0 0.0.0.255 log
 permit udp XXX.XXX.10.0 0.0.0.255 host XXX.XXX.10.254 eq domain
 permit tcp XXX.XXX.10.0 0.0.0.255 host XXX.XXX.10.254 eq domain
 permit udp host XXX.XXX.10.62 any eq domain
 permit tcp host XXX.XXX.10.62 any eq domain
 deny   udp any any eq domain log
 deny   tcp any any eq domain log
 permit ip XXX.XXX.10.0 0.0.0.255 any
 deny   ip any any log
ip access-list extended ACL-NAT-INSIDE
 deny   ip XXX.XXX.10.0 0.0.0.255 YYY.YYY.0.0 0.0.255.255
 permit ip XXX.XXX.10.0 0.0.0.255 any
ip access-list extended ACL-VPN-S2S-R003
 permit ip XXX.XXX.10.0 0.0.0.255 YYY.YYY.5.0 0.0.0.255
ip access-list extended ACL-VPN-S2S-R003-FILTER-IN
 permit ip YYY.YYY.5.0 0.0.0.255 host XXX.XXX.10.14
 permit ip YYY.YYY.5.0 0.0.0.255 host XXX.XXX.10.62
 permit ip YYY.YYY.5.0 0.0.0.255 host XXX.XXX.10.116
 permit ip YYY.YYY.5.0 0.0.0.255 host XXX.XXX.10.201
 permit ip YYY.YYY.5.0 0.0.0.255 host XXX.XXX.10.202
 permit icmp YYY.YYY.5.0 0.0.0.255 XXX.XXX.10.0 0.0.0.255 echo
 deny   ip any any log
!
!
!
!
!
!
!
!
control-plane
!
!
!
line con 0
line aux 0
line vty 0 4
 logging synchronous
 transport preferred none
 transport input ssh
line vty 5 15
 logging synchronous
 transport preferred none
 transport input ssh
!
scheduler allocate 20000 1000
end

R-002#
Pozdrawiam...
Marceli

MarcelLee
wannabe
wannabe
Posty: 75
Rejestracja: 26 wrz 2005, 21:44
Lokalizacja: Sopot

#2

#2 Post autor: MarcelLee »

zainspirowany wypowiedzią http://ccie.pl/viewtopic.php?p=147205#147205 wyłączyłem wszystkie logi w ACL, różnicy nie widać...

Kod: Zaznacz cały

R-002#sh proc cpu history

R-002   11:07:25 AM Tuesday Dec 30 2014 UTC




      888888888666688888777778888888888888887777777777777778888877
      555500000666688888777776666677777000005555566666999990000033
  100
   90 ****         *****     **********
   80 *********    *********************************************
   70 ************************************************************
   60 ************************************************************
   50 ************************************************************
   40 ************************************************************
   30 ************************************************************
   20 ************************************************************
   10 ************************************************************
     0....5....1....1....2....2....3....3....4....4....5....5....6
               0    5    0    5    0    5    0    5    0    5    0
               CPU% per second (last 60 seconds)




      888899985111 66666677777421113222112527788788777771541211241
      396703101525648326607188493992505906290775031499003501155262
  100
   90  ******                                 **
   80 #######*            * **               *#* ** **
   70 ########      *  *****#*              *###*##*###*
   60 ########     *##########              *##########* *
   50 ########*    *##########            * ############ *      *
   40 ########*    ###########*           * ############ **     *
   30 #########    ###########**   ** *  ***############ #*     *
   20 #########* * ############* ******* ***############ ## ****#
   10 #########*##*#####################*#########################
     0....5....1....1....2....2....3....3....4....4....5....5....6
               0    5    0    5    0    5    0    5    0    5    0
               CPU% per minute (last 60 minutes)
              * = maximum CPU%   # = average CPU%




      997353434376594784999999988445555757544454442577454554844345345444435352
      958437888659094029899969222500116920366836036806729025817811882641674124
  100 **           *    ******
   90 **           *    *******                             *
   80 ***       *  *  * *********      *             *      *
   70 ***       ** * ** **#******      * *          **      *
   60 *#*       ** * ** *###*****     ** *         ***      *
   50 *#* * * * **** ****###*#**** *************   ********** *  * ***  * * *
   40 *#* ***************###*#******************** ************************ *
   30 ###****************###*#***********************************************
   20 ###***************########**********************************************
   10 ###***************#########******#**************************************
     0....5....1....1....2....2....3....3....4....4....5....5....6....6....7..
               0    5    0    5    0    5    0    5    0    5    0    5    0
                   CPU% per hour (last 72 hours)
                  * = maximum CPU%   # = average CPU%



R-002#sh proc cpu sorted 1min | e 0.00%  0.00%  0.00%
CPU utilization for five seconds: 78%/76%; one minute: 80%; five minutes: 73%
 PID Runtime(ms)     Invoked      uSecs   5Sec   1Min   5Min TTY Process
  95     2387312   148027610         16  0.88%  0.65%  0.63%   0 Ethernet Msec Ti
  28       13844        2747       5039  0.56%  0.33%  0.43% 194 SSH Process
 120    18316472     5010172       3655  0.32%  0.28%  0.42%   0 IP Input
   2      180108      239649        751  0.08%  0.25%  0.29%   0 Load Meter
 297     3480944     1681899       2069  0.08%  0.22%  0.44%   0 DNS Server
   5     2138608      213868       9999  0.00%  0.12%  0.13%   0 Check heaps
 116      675364    36882391         18  0.16%  0.12%  0.13%   0 IPAM Manager
 298     1868708      464670       4021  0.08%  0.10%  0.28%   0 DNS Server Input
  29     1443536     2668912        540  0.08%  0.05%  0.07%   0 ARP Input
  94      165712     7296074         22  0.08%  0.03%  0.01%   0 Ethernet Timer C
  63      633904       42789      14814  0.00%  0.03%  0.00%   0 Per-minute Jobs
 237       21588     1197995         18  0.00%  0.02%  0.00%   0 Crypto Device Up
  64      123840     1199570        103  0.08%  0.02%  0.00%   0 Per-Second Jobs
 146      245292       19968      12284  0.00%  0.02%  0.00%   0 Licensing Auto U
 178      134916     2335754         57  0.08%  0.02%  0.01%   0 Inspect process
 173      137340     1562295         87  0.00%  0.02%  0.01%   0 CEF: IPv4 proces
 132      112192     4676581         23  0.00%  0.01%  0.00%   0 SSS Feature Time
 242      110328     5984005         18  0.00%  0.01%  0.00%   0 Atheros LED Ctro
 291      110888     2335675         47  0.00%  0.01%  0.00%   0 IP NAT Ager
 166       40808     1197683         34  0.08%  0.00%  0.00%   0 RUDPV1 Main Proc
 226      149072      103188       1444  0.00%  0.00%  0.02%   0 Crypto IKMP
R-002#

Pozdrawiam...
Marceli

Awatar użytkownika
drake
CCIE
CCIE
Posty: 1593
Rejestracja: 06 maja 2005, 01:32
Lokalizacja: Dortmund, DE
Kontakt:

#3

#3 Post autor: drake »

Hej,
pokaz wynik komend:

Kod: Zaznacz cały

show ip traffic
show interface fasteth0 switching
show interface fasteth0 summary
Polecam w tej konfiguracji:
1. na interfejsie WAN wylaczyc proxy-arp, ip redirects
2. na interfjesie LAN to samo, plus zmniejszyc TCP MSS do 1300, bo masz ruch ktory idzie w VPN. Sadze ze router fragmentuje i stad obciazenie. Pierwsza wyzej wskazana komenda powinna nieco naswietlic problemy...

Pozdruffka! ;)
Never stop exploring :)

https://iverion.de

MarcelLee
wannabe
wannabe
Posty: 75
Rejestracja: 26 wrz 2005, 21:44
Lokalizacja: Sopot

#4

#4 Post autor: MarcelLee »

Drake, dziękuję za odpowiedź, proxy-arp już wyłączony, o reszcie muszę poczytać, żeby świadomie działać ;-)
drake pisze: pokaz wynik komend:

Kod: Zaznacz cały

show ip traffic
show interface fasteth0 switching
show interface fasteth0 summary

Kod: Zaznacz cały

R-002#show ip traffic
IP statistics:
  Rcvd:  22274894 total, 966006 local destination
         1371 format errors, 0 checksum errors, 5 bad hop count
         0 unknown protocol, 0 not a gateway
         0 security failures, 0 bad options, 0 with options
  Opts:  0 end, 0 nop, 0 basic security, 0 loose source route
         0 timestamp, 0 extended security, 0 record route
         0 stream ID, 0 strict source route, 0 alert, 0 cipso, 0 ump
         0 other
  Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble
         0 fragmented, 0 fragments, 0 couldn't fragment
  Bcast: 429454 received, 2026 sent
  Mcast: 0 received, 0 sent
  Sent:  864283 generated, 249539252 forwarded
  Drop:  1523 encapsulation failed, 0 unresolved, 0 no adjacency
         2432 no route, 0 unicast RPF, 0 forced drop
         0 options denied
  Drop:  0 packets with source IP address zero
  Drop:  0 packets with internal loop back IP address
         637 physical broadcast
  Reinj: 0 in input feature path, 0 in output feature path

ICMP statistics:
  Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 2322 unreachable
        114 echo, 156 echo reply, 0 mask requests, 0 mask replies, 0 quench
        0 parameter, 0 timestamp, 0 timestamp replies, 0 info request, 0 other
        0 irdp solicitations, 0 irdp advertisements
        0 time exceeded, 0 info replies
  Sent: 2 redirects, 53235 unreachable, 291 echo, 114 echo reply
        0 mask requests, 0 mask replies, 0 quench, 0 timestamp, 0 timestamp replies
        0 info reply, 5 time exceeded, 0 parameter problem
        0 irdp solicitations, 0 irdp advertisements

TCP statistics:
  Rcvd: 45484 total, 0 checksum errors, 2590 no port
  Sent: 46373 total

BGP statistics:
  Rcvd: 0 total, 0 opens, 0 notifications, 0 updates
        0 keepalives, 0 route-refresh, 0 unrecognized
  Sent: 0 total, 0 opens, 0 notifications, 0 updates
        0 keepalives, 0 route-refresh

EIGRP-IPv4 statistics:
  Rcvd: 0 total
  Sent: 0 total

PIMv2 statistics: Sent/Received
  Total: 0/0, 0 checksum errors, 0 format errors
  Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0,  Hellos: 0/0
  Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0
  Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0
  Queue drops: 0
  State-Refresh: 0/0

IGMP statistics: Sent/Received
  Total: 0/0, Format errors: 0/0, Checksum errors: 0/0
  Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0
  DVMRP: 0/0, PIM: 0/0
  Queue drops: 0

UDP statistics:
  Rcvd: 917930 total, 3 checksum errors, 289141 no port
  Sent: 763581 total, 0 forwarded broadcasts

OSPF statistics:
  Last clearing of OSPF traffic counters never

  Rcvd: 0 total, 0 checksum errors
        0 hello, 0 database desc, 0 link state req
        0 link state updates, 0 link state acks

  Sent: 0 total
        0 hello, 0 database desc, 0 link state req
        0 link state updates, 0 link state acks

ARP statistics:
  Rcvd: 2749350 requests, 217 replies, 0 reverse, 0 other
  Sent: 941 requests, 110900 replies (159 proxy), 0 reverse
  Drop due to input queue full: 0
R-002#show interface fastEthernet 0/0 switching
FastEthernet0/0 OUTSIDE 25/8
          Throttle count       7619
                   Drops         RP          0         SP          0
             SPD Flushes       Fast          0        SSE          0
             SPD Aggress       Fast          0
            SPD Priority     Inputs    2664206      Drops          0

    Protocol  IP
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process   20990834 3917389452    1284380  110352819
            Cache misses          0          -          -          -
                    Fast  141444256 2206791902   90279997  766823170
               Auton/SSE          0          0          0          0

    Protocol  DEC MOP
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process          0          0       1995     153615
            Cache misses          0          -          -          -
                    Fast          0          0          0          0
               Auton/SSE          0          0          0          0

    Protocol  ARP
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process    2661441  159879144      33509    2010540
            Cache misses          0          -          -          -
                    Fast          0          0          0          0
               Auton/SSE          0          0          0          0

    Protocol  CDP
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process      48102    5934329       3556    1259027
            Cache misses          0          -          -          -
                    Fast          0          0          0          0
               Auton/SSE          0          0          0          0

    Protocol  Other
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process     622863   72955652     120121    7207260
            Cache misses          0          -          -          -
                    Fast          0          0          0          0
               Auton/SSE          0          0          0          0

    NOTE: all counts are cumulative and reset only after a reload.
R-002#show interface fastEthernet 0/0 sum

 *: interface is up
 IHQ: pkts in input hold queue     IQD: pkts dropped from input queue
 OHQ: pkts in output hold queue    OQD: pkts dropped from output queue
 RXBS: rx rate (bits/sec)          RXPS: rx rate (pkts/sec)
 TXBS: tx rate (bits/sec)          TXPS: tx rate (pkts/sec)
 TRTL: throttle count

  Interface                   IHQ       IQD       OHQ       OQD      RXBS      RXPS      TXBS      TXPS      TRTL
-----------------------------------------------------------------------------------------------------------------
* FastEthernet0/0               0         0         0         0    443000        51     42000        24       134
R-002#
Pozdrawiam...
Marceli

martino76
CCIE
CCIE
Posty: 883
Rejestracja: 17 gru 2010, 15:23
Lokalizacja: Barczewo

#5

#5 Post autor: martino76 »

MarcelLee pisze:Drake, dziękuję za odpowiedź, proxy-arp już wyłączony, o reszcie muszę poczytać, żeby świadomie działać ;-)
drake pisze: pokaz wynik komend:

Kod: Zaznacz cały

show ip traffic
show interface fasteth0 switching
show interface fasteth0 summary

Kod: Zaznacz cały

R-002#show ip traffic
IP statistics:
  Rcvd:  22274894 total, 966006 local destination
         1371 format errors, 0 checksum errors, 5 bad hop count
         0 unknown protocol, 0 not a gateway
         0 security failures, 0 bad options, 0 with options
  Opts:  0 end, 0 nop, 0 basic security, 0 loose source route
         0 timestamp, 0 extended security, 0 record route
         0 stream ID, 0 strict source route, 0 alert, 0 cipso, 0 ump
         0 other
  Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble
         0 fragmented, 0 fragments, 0 couldn't fragment
  Bcast: 429454 received, 2026 sent
  Mcast: 0 received, 0 sent
  Sent:  864283 generated, 249539252 forwarded
  Drop:  1523 encapsulation failed, 0 unresolved, 0 no adjacency
         2432 no route, 0 unicast RPF, 0 forced drop
         0 options denied
  Drop:  0 packets with source IP address zero
  Drop:  0 packets with internal loop back IP address
         637 physical broadcast
  Reinj: 0 in input feature path, 0 in output feature path

ICMP statistics:
  Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 2322 unreachable
        114 echo, 156 echo reply, 0 mask requests, 0 mask replies, 0 quench
        0 parameter, 0 timestamp, 0 timestamp replies, 0 info request, 0 other
        0 irdp solicitations, 0 irdp advertisements
        0 time exceeded, 0 info replies
  Sent: 2 redirects, 53235 unreachable, 291 echo, 114 echo reply
        0 mask requests, 0 mask replies, 0 quench, 0 timestamp, 0 timestamp replies
        0 info reply, 5 time exceeded, 0 parameter problem
        0 irdp solicitations, 0 irdp advertisements

TCP statistics:
  Rcvd: 45484 total, 0 checksum errors, 2590 no port
  Sent: 46373 total

BGP statistics:
  Rcvd: 0 total, 0 opens, 0 notifications, 0 updates
        0 keepalives, 0 route-refresh, 0 unrecognized
  Sent: 0 total, 0 opens, 0 notifications, 0 updates
        0 keepalives, 0 route-refresh

EIGRP-IPv4 statistics:
  Rcvd: 0 total
  Sent: 0 total

PIMv2 statistics: Sent/Received
  Total: 0/0, 0 checksum errors, 0 format errors
  Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0,  Hellos: 0/0
  Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0
  Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0
  Queue drops: 0
  State-Refresh: 0/0

IGMP statistics: Sent/Received
  Total: 0/0, Format errors: 0/0, Checksum errors: 0/0
  Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0
  DVMRP: 0/0, PIM: 0/0
  Queue drops: 0

UDP statistics:
  Rcvd: 917930 total, 3 checksum errors, 289141 no port
  Sent: 763581 total, 0 forwarded broadcasts

OSPF statistics:
  Last clearing of OSPF traffic counters never

  Rcvd: 0 total, 0 checksum errors
        0 hello, 0 database desc, 0 link state req
        0 link state updates, 0 link state acks

  Sent: 0 total
        0 hello, 0 database desc, 0 link state req
        0 link state updates, 0 link state acks

ARP statistics:
  Rcvd: 2749350 requests, 217 replies, 0 reverse, 0 other
  Sent: 941 requests, 110900 replies (159 proxy), 0 reverse
  Drop due to input queue full: 0
R-002#show interface fastEthernet 0/0 switching
FastEthernet0/0 OUTSIDE 25/8
          Throttle count       7619
                   Drops         RP          0         SP          0
             SPD Flushes       Fast          0        SSE          0
             SPD Aggress       Fast          0
            SPD Priority     Inputs    2664206      Drops          0

    Protocol  IP
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process   20990834 3917389452    1284380  110352819
            Cache misses          0          -          -          -
                    Fast  141444256 2206791902   90279997  766823170
               Auton/SSE          0          0          0          0

    Protocol  DEC MOP
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process          0          0       1995     153615
            Cache misses          0          -          -          -
                    Fast          0          0          0          0
               Auton/SSE          0          0          0          0

    Protocol  ARP
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process    2661441  159879144      33509    2010540
            Cache misses          0          -          -          -
                    Fast          0          0          0          0
               Auton/SSE          0          0          0          0

    Protocol  CDP
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process      48102    5934329       3556    1259027
            Cache misses          0          -          -          -
                    Fast          0          0          0          0
               Auton/SSE          0          0          0          0

    Protocol  Other
          Switching path    Pkts In   Chars In   Pkts Out  Chars Out
                 Process     622863   72955652     120121    7207260
            Cache misses          0          -          -          -
                    Fast          0          0          0          0
               Auton/SSE          0          0          0          0

    NOTE: all counts are cumulative and reset only after a reload.
R-002#show interface fastEthernet 0/0 sum

 *: interface is up
 IHQ: pkts in input hold queue     IQD: pkts dropped from input queue
 OHQ: pkts in output hold queue    OQD: pkts dropped from output queue
 RXBS: rx rate (bits/sec)          RXPS: rx rate (pkts/sec)
 TXBS: tx rate (bits/sec)          TXPS: tx rate (pkts/sec)
 TRTL: throttle count

  Interface                   IHQ       IQD       OHQ       OQD      RXBS      RXPS      TXBS      TXPS      TRTL
-----------------------------------------------------------------------------------------------------------------
* FastEthernet0/0               0         0         0         0    443000        51     42000        24       134
R-002#

Masz sporo pakietow IP, ktore leca do CPU i moze byc wiele przyczyn.

Chociaz patrzac na powyzszy output mozna wyeliminowac brodcast, mimo iz jest troche pakietow oraz multicast, ktorego wogole nie widac na urzadzeniu

Moze to byc MTU dla tunnelu i wymagana fragementacja tak jak napisal kolega drake albo cos innego.

Najlepiej byloby jak bys podeslal config obylo by sie bez zgadywania.

[EDIT] Ewentualnie zerknij na link

Pozdro,

MarcelLee
wannabe
wannabe
Posty: 75
Rejestracja: 26 wrz 2005, 21:44
Lokalizacja: Sopot

#6

#6 Post autor: MarcelLee »

drake pisze: wylaczyc proxy-arp, ip redirects
zrobione, jeszcze raz dziękuję za te sugestie.
drake pisze: zmniejszyc TCP MSS do 1300, bo masz ruch ktory idzie w VPN. Sadze ze router fragmentuje i stad obciazenie. Pierwsza wyzej wskazana komenda powinna nieco naswietlic problemy...
Nie bardzo rozumiem skąd się bierze 1300, może mi ktoś to wytłumaczyć?
Rozumiem że MSS to de facto ilość danych w ramce wpychanej do medium, czyli ilość danych musi być mniejsza od MTU bo w MTU muszą się jeszcze znaleźć nagłówki.
Rozumiem, że w przypadku VPN jest jeszcze dodatkowy narzut i temat jeszcze bardziej się komplikuje, ale przy założeniu połączenia bez VPN powinno być łatwiej zrozumieć.
Mając MTU 1500 i 20 bajtów na nagłówki daje MSS 1480 http://en.wikipedia.org/wiki/Transmissi ... _structure
Mój router może maksymalnie ustanowić 1460, co już wskazuje że mam jakąś lukę w wiedzy ;)

Kod: Zaznacz cały

R-002(config)#int fa 0/0
R-002(config-if)#ip tcp adjust-mss ?
  <500-1460>  Maximum segment size in bytes
martino76 pisze: Najlepiej byloby jak bys podeslal config obylo by sie bez zgadywania.
Cały config leży w pierwszym poście ;)
Pozdrawiam...
Marceli

Awatar użytkownika
mstan
wannabe
wannabe
Posty: 94
Rejestracja: 18 lip 2013, 18:21

#7

#7 Post autor: mstan »

Troche czasu minelo i nie wiem czy problem nadal wystepuje, jesli tak to warto sprawdzic:

Kod: Zaznacz cały

#show ip cef switching statistics 
#show ip cef switching statistics feature
Tak jak w podobnym watku, ktory przytoczono wczesniej.

Jesli chodzi o statystyki/bledy na interfejsie:
7829 input errors, 0 CRC, 0 frame, 1 overrun, 7827 ignored
Zarowno 'overrun' jak i 'ignored' odnosza sie do nadmiernej ilosci ruchu, ktory przychodzi do routera i przekracza jego mozliwosci.
Istnieje delikatna roznica miedzy tymi counterami, ale generalnie przyczyna jest podobna.

Zwykle wchodza w gre tzw "microbursts", czyli nieuchwytne dla polecen IOSa bardzo krotkie (ponizej 1 sek) okresy czasu, gdzie przychodzi wiecej ruchu niz interfejs/CPU jest w stanie obsluzyc. Konkretnie, chodzi tutaj o rozmiar tzw 'rx ring' na interfejsie (rozmiar widac w "show controllers") i aktualna zajetosc CPU.

Czesto ciezko uwierzyc w wystapienie "microbursts", gdyz sredni input rate w 'show interface' jest niewielki.
W Twoim przypadku przykladowy output pokazuje ok 4 Mbps.

Kod: Zaznacz cały

 5 minute input rate 4181000 bits/sec, 381 packets/sec 
Niestety, to jest srednia za ostatnie 5 minut. Minimalny okres usredniania w IOS to 30 sekund. Bedzie to troche lepsze przyblizenie, ale wciaz malo precyzyjne.

Zeby udowodnic istnienie "microbursts" nalezy wykonac packet capture (np SPAN na switchu na interfejsie w strone routera) i sprawdzic dokladne timestampy dla kolejnych pakietow.
W ten sposob mozna wyliczyc rzeczywisty input rate.

U Ciebie widzimy rowniez duze obciazenie procesora w przerwaniach, wiec najpierw mozna sie temu przyjrzec zbierajac outputy, ktore wymienilem na wstepie.

ODPOWIEDZ