check if you are using "ip accounting output-packets" on your interfaces. If there are a lot of of small packets ,accounting table gets overflowed, and you will get high cpu. We had this problem year ago, it took several days to find out the reason :) And today we had it again on one router, but it took just couple of seconds to figure out that one of our client was hit by DDos and, ironicaly, he had this command on interface.
During attack: CPU utilization for five seconds: 82%/76%; one minute: 86%; five minutes: 90% After we removed ip accounting output-packets from interface: CPU utilization for five seconds: 59%/56%; one minute: 59%; five minutes: 63% Cool, huh? check out output of sh ip accounting output-packets > For information, the problem moved from one router to another identical > one and I can see the exact same symptoms. Gotta find the guilty bastard ;-) _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
