check if you are using "ip accounting output-packets" on your interfaces. If 
there are a lot of of small packets ,accounting table gets overflowed, and you 
will get high cpu. We had this problem year ago, it took several days to find 
out the reason :) And today we had it again on one router, but it took just 
couple of seconds to figure out that one of our client was hit by DDos and, 
ironicaly, he had this command on interface.

During attack:

CPU utilization for five seconds: 82%/76%; one minute: 86%; five minutes: 90%

After we removed ip accounting output-packets from interface:

CPU utilization for five seconds: 59%/56%; one minute: 59%; five minutes: 63%


Cool, huh?


check out output of 

sh ip accounting output-packets 



> For information, the problem moved from one router to another identical
> one and I can see the exact same symptoms. Gotta find the guilty bastard ;-)
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to