Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Cisco: NSP

Re: 6500 - What determines whether certain traffic is punted or not?

 

 

Cisco nsp RSS feed   Index | Next | Previous | View Threaded


p.mayers at imperial

Nov 24, 2009, 12:09 PM

Post #1 of 2 (406 views)
Permalink
Re: 6500 - What determines whether certain traffic is punted or not?

Drew Weaver wrote:
> Howdy,
>
> I've been having some issues with queue drops/CLI sluggishness on a
> 6500 and I wanted to check what kind of volume of traffic I was
> getting punted to the RP.
>
> I made a span session and began checking out the traffic with
> tethereal.
>
> It seems like a huge (30,000) or so packets every few seconds of just
> UDP traffic is being punted.
>
> The system is a Sup720-3BXL.

What's the IOS version? As posted recently, I've seen FIB/TCAM
programming errors on some IOSes; try a "shut", "no shut" of the input
interfaces (if you can)

All kinds of things can cause CPU punts, but primarily you're looking
for MTU failures, ICMP redirects (packets coming in on an interface
which is also the outbound interface), glean (next-hop needs ARP) and
similar.

Obviously if you've somehow managed to fall back to CPU forwarding, but
that's unlikely from the sounds of it.

Bear in mind that certain kinds of traffic (e.g. RPF failures) are
"leaked" to the CPU so that it can see & count them; do you have any MLS
rate-limiters enabled ("sh mls rate-limit")
_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


dean at eatworms

Nov 24, 2009, 11:22 AM

Post #2 of 2 (374 views)
Permalink
Re: 6500 - What determines whether certain traffic is punted or not? [In reply to]

Having spent the day chasing something identical.....for us is was that the
traffic was being redirected to another router on the inbound VLAN - every
packet needing a redirect gets punted. A few changes to topology and the
redirect requirement was removed and the traffic returned to being hardware
routed.

We also had span the RP before we worked out why the traffic was being
punted.

Dean

-----Original Message-----
From: cisco-nsp-bounces [at] puck
[mailto:cisco-nsp-bounces [at] puck] On Behalf Of Drew Weaver
Sent: 24 November 2009 16:33
To: Cisco-nsp
Subject: [c-nsp] 6500 - What determines whether certain traffic is punted or
not?

Howdy,

I've been having some issues with queue drops/CLI sluggishness on a 6500 and
I wanted to check what kind of volume of traffic I was getting punted to the
RP.

I made a span session and began checking out the traffic with tethereal.

It seems like a huge (30,000) or so packets every few seconds of just UDP
traffic is being punted.

The system is a Sup720-3BXL.

Does anyone know how to determine what kind of traffic should be punted to
the RP and more importantly why this UDP traffic is hitting the RP?

It almost looks like p2p traffic, but I also see other types of traffic, tcp
445, DNS, port 80, etc.

thanks,
-Drew

_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Cisco nsp RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.