Столкнулся с проблемой большой загрузки на Cisco 2620. Периодически маршрутизатор загружается на 100% и даже связь с ним теряется.
Вот пример загрузки железяки:
rtr1-len1#sh proc cpu | e 0.00% 0.00% 0.00%
CPU utilization for five seconds: 74%/66%; one minute: 89%; five minutes: 61%
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
4 1081452 33774 32020 0.00% 0.16% 0.10% 0 VTEMPLATE Backgr
6 5950500 442689 13441 0.00% 0.19% 0.13% 0 Check heaps
7 590088 6125 96340 0.00% 0.01% 0.00% 0 Pool Manager
12 36390328 32426350 1122 2.07% 1.32% 1.27% 0 ARP Input
13 118680 620966 191 0.07% 0.01% 0.00% 0 HC Counter Timer
19 42684 2487314 17 0.00% 0.01% 0.00% 0 GraphIt
22 215360 376878 571 0.00% 0.01% 0.00% 0 Net Background
25 102728 2487596 41 0.07% 0.02% 0.00% 0 Per-Second Jobs
34 1887776 499474 3779 0.15% 0.09% 0.08% 0 Compute load avg
35 3365044 43613 77156 0.00% 0.04% 0.05% 0 Per-minute Jobs
39 564912 908486 621 0.15% 0.09% 0.06% 0 AAA ACCT Proc
40 330928 888477 372 0.15% 0.09% 0.05% 0 ACCT Periodic Pr
43 75439808 64023768 1178 2.87% 2.26% 2.84% 0 IP Input
52 190564 9689112 19 0.00% 0.01% 0.00% 0 SSS Feature Time
53 734664 470901 1560 0.07% 0.07% 0.02% 0 TCP Timer
59 283156 151123 1873 0.00% 0.02% 0.00% 0 IP Background
61 331196 41884 7907 0.00% 0.04% 0.00% 0 Adj Manager
64 219044 112660 1944 0.07% 0.02% 0.00% 0 DHCPD Receive
65 148108 41588 3561 0.15% 0.03% 0.00% 0 IP Cache Ager
81 892248 413144 2159 0.55% 0.26% 0.27% 0 CEF process
107 51448 9102 5652 0.00% 0.02% 0.00% 0 CEF Scanner
109 5033776 21941 229433 0.00% 6.24% 1.85% 0 Key Proc
128 3502432 7136468 490 0.07% 0.06% 0.07% 0 L2X Data Daemon
131 1539584 1870424 823 0.00% 0.07% 0.08% 0 PPTP Mgmt
132 811188 789772 1027 0.07% 0.02% 0.00% 0 PPTP Data
133 220324 972993 226 0.00% 0.01% 0.00% 0 TCP Driver
135 987576 6099987 161 0.07% 0.04% 0.04% 0 IP NAT Ager
136 2513500 76257652 32 0.15% 0.13% 0.07% 0 PPP manager
137 1667340 76417918 21 0.31% 0.23% 0.15% 0 PPP Events
138 100728 2484050 40 0.07% 0.00% 0.00% 0 Multilink PPP
146 429444 2621180 163 0.00% 0.01% 0.00% 0 NAT MIB Helper
147 3819180 2449921 1558 0.31% 0.25% 0.24% 0 RADIUS
150 620 73 8493 0.55% 0.25% 0.05% 66 Virtual ExecИз списка процессов ничего железяку не загружает. Что же тогда её грузит так сильно?
>rtr1-len1#sh proc cpu | e 0.00% 0.00% 0.00%
>CPU utilization for five seconds: 74%/66%; one minute: 89%; five minutes: 61%From cisco.com: CPU utilization for the last 5 seconds. The second number indicates the percent of CPU time spent at the interrupt level.
66% это прерывания. Скорее всего циска не справляется с объемом трафика.
В этом случае полезно иметь графики загрузки процессора и загрузки интерфейсов (Mb/s и pps). Если значения pps близки к тем, что пишутся в "router performance", то железку надо апгрейдить.
>>rtr1-len1#sh proc cpu | e 0.00% 0.00% 0.00%
>>CPU utilization for five seconds: 74%/66%; one minute: 89%; five minutes: 61%
>
>From cisco.com: CPU utilization for the last 5 seconds. The second number
>indicates the percent of CPU time spent at the interrupt level.
>
>
>66% это прерывания. Скорее всего циска не справляется с объемом трафика.
>
>В этом случае полезно иметь графики загрузки процессора и загрузки интерфейсов (Mb/s
>и pps). Если значения pps близки к тем, что пишутся в
>"router performance", то железку надо апгрейдить.При наличии партнёрского доступа, можно запихнуть вывод sh tech-support в Output-Interpreter и почитать, что сама циска об этом думает.
>>rtr1-len1#sh proc cpu | e 0.00% 0.00% 0.00%
>>CPU utilization for five seconds: 74%/66%; one minute: 89%; five minutes: 61%
>
>From cisco.com: CPU utilization for the last 5 seconds. The second number
>indicates the percent of CPU time spent at the interrupt level.
>
>
>66% это прерывания. Скорее всего циска не справляется с объемом трафика.
>
>В этом случае полезно иметь графики загрузки процессора и загрузки интерфейсов (Mb/s
>и pps). Если значения pps близки к тем, что пишутся в
>"router performance", то железку надо апгрейдить.# sh interfaces
FastEthernet0/0 is up, line protocol is up
Hardware is AmdFE, address is 0006.53af.e6e0 (bia 0006.53af.e6e0)
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 29/255, rxload 29/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s, 100BaseTX/FX
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 2/75/1130237/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 11420000 bits/sec, 1208 packets/sec
5 minute output rate 11597000 bits/sec, 1076 packets/sec
510634103 packets input, 181919261 bytes
Received 82659193 broadcasts, 0 runts, 0 giants, 0 throttles
979 input errors, 0 CRC, 0 frame, 979 overrun, 0 ignored
0 watchdog
0 input packets with dribble condition detected
337113640 packets output, 2315217737 bytes, 0 underruns
0 output errors, 0 collisions, 2 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped outПараметр packets/sec доходит до 1500.
Я посмотрел спецификацию по скорости на мою Cisco 2620:
Process switching
packets/s = 1500
Мбит/с = 0,768Fast/CEF Switching
packets/s = 25000
Мбит/с = 12,80Я еще заметил, что у меня в таблице трансляции адресов очень много записей (sh ip net translation)
Обидно то, что перегрузка эта случается где-то раз в неделю и длится минут 10, а потом нагрузка не бывает больше 20%.
Что вы думаете по этому поводу?
А пришли sh tech-support почтой, посмотрим что циска скажет moia-pochta (@) yandex.ru
sh int switching покажите..
>sh int switching покажите..FastEthernet0/0
Throttle count 0
Drops RP 1173923 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 61179767 Drops 410527Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 76936672 871399914 57090703 3305513464
Cache misses 35 - - -
Fast 377589413 2148915583 292723009 2064955154
Auton/SSE 0 0 0 0Protocol ARP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 61179087 3671249886 4420186 300572648
Cache misses 0 - - -
Fast 0 0 0 0
Auton/SSE 0 0 0 0Protocol CDP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 48334 19190832 48715 20635189
Cache misses 0 - - -
Fast 0 0 0 0
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 1698365 178367656 291101 17466060
Cache misses 0 - - -
Fast 15565 2033498 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access1All statistics for this interface are zero.
Virtual-Template1All statistics for this interface are zero.
Virtual-Access2
Throttle count 0
Drops RP 128 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1531 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 529319 82213473 142647 44855456
Cache misses 0 - - -
Fast 0 4230784520 2027340 1117034948
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1463 32971
Cache misses 0 - - -
Fast 1484075 198762499 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access3
Throttle count 0
Drops RP 105 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1443 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 644003 83030323 221504 103402453
Cache misses 0 - - -
Fast 0 4254945500 1430091 572184554
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1553 34550
Cache misses 0 - - -
Fast 961241 132480530 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access4
Throttle count 0
Drops RP 1992 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1403 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 396862 33026531 127462 25212559
Cache misses 0 - - -
Fast 0 4237574481 1757416 980951756
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1513 33724
Cache misses 0 - - -
Fast 1332459 190923666 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access5
Throttle count 0
Drops RP 1233 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1275 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 429033 58422089 144032 17344868
Cache misses 0 - - -
Fast 0 4236345771 1637325 746655891
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1323 29265
Cache misses 0 - - -
Fast 1391313 187080179 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access6
Throttle count 0
Drops RP 96 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1396 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 397598 44501992 130388 23198467
Cache misses 0 - - -
Fast 0 4237896184 1620584 638077654
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1489 33305
Cache misses 0 - - -
Fast 1342439 200580527 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access7
Throttle count 0
Drops RP 421 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1334 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 813104 70784200 261564 39192436
Cache misses 0 - - -
Fast 0 4230667973 2130286 871555360
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1322 29520
Cache misses 0 - - -
Fast 1577423 232829485 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access8
Throttle count 0
Drops RP 54 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1318 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 812458 97812534 290263 59046283
Cache misses 0 - - -
Fast 0 4205024113 2824316 1750659184
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1355 30365
Cache misses 0 - - -
Fast 2083509 455730574 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access9
Throttle count 0
Drops RP 56 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1440 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 444751 35174772 144422 23924653
Cache misses 0 - - -
Fast 0 4223877349 1976054 967816703
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 3 541 1503 33583
Cache misses 0 - - -
Fast 1705042 291337238 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access10
Throttle count 0
Drops RP 73 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1337 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 555171 39678012 184234 24789716
Cache misses 0 - - -
Fast 0 4243520969 1732985 993638465
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1350 29960
Cache misses 0 - - -
Fast 1204163 221440813 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access11
Throttle count 0
Drops RP 734 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1158 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 314423 27761395 115627 33428174
Cache misses 0 - - -
Fast 0 4222187840 1968045 1036583011
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 3 476 1293 28840
Cache misses 0 - - -
Fast 1726436 243360385 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access12
Throttle count 0
Drops RP 1136 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1400 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 376126 35302853 92570 16173955
Cache misses 0 - - -
Fast 0 4246091524 1437909 662154156
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1487 33155
Cache misses 0 - - -
Fast 1154219 168286167 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access13
Throttle count 0
Drops RP 6 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1334 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 574681 46703344 139185 32698025
Cache misses 0 - - -
Fast 0 4235725608 1974232 1045988894
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1308 29754
Cache misses 0 - - -
Fast 1396518 207933257 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access14
Throttle count 0
Drops RP 243 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1348 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 528882 46731313 117956 19789518
Cache misses 0 - - -
Fast 0 4238955231 1615238 865829036
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1355 30416
Cache misses 0 - - -
Fast 1323700 196128981 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access15
Throttle count 0
Drops RP 20 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1201 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 441026 35228690 121946 20698555
Cache misses 0 - - -
Fast 0 4207363255 2535358 976536486
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1266 28633
Cache misses 0 - - -
Fast 2042310 278173680 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access16
Throttle count 0
Drops RP 330 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1370 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 424384 46726381 156332 19034557
Cache misses 0 - - -
Fast 0 4220415936 2126485 907645254
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1386 31176
Cache misses 0 - - -
Fast 1743536 243057552 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access17
Throttle count 0
Drops RP 6 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1436 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 751118 59722900 259350 50228852
Cache misses 0 - - -
Fast 0 4227872680 2147470 1253070062
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1446 32169
Cache misses 0 - - -
Fast 1559219 258748264 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access18
Throttle count 0
Drops RP 60 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1479 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 596868 51458807 172134 32505591
Cache misses 0 - - -
Fast 0 4230065166 2035975 911528564
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1452 32401
Cache misses 0 - - -
Fast 1523300 217194360 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access19
Throttle count 0
Drops RP 44 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1581 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 628292 54950753 163266 57682922
Cache misses 0 - - -
Fast 0 4249257360 1619135 752112940
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1668 37167
Cache misses 0 - - -
Fast 1074092 213716923 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access20
Throttle count 0
Drops RP 122 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1624 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 558196 53701790 203414 84597407
Cache misses 0 - - -
Fast 0 4217290085 2333995 1382341323
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1651 36565
Cache misses 0 - - -
Fast 1789825 259234172 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access21
Throttle count 0
Drops RP 141 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1525 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 559279 47576951 154289 30003430
Cache misses 0 - - -
Fast 0 4228400513 1843180 1130340913
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 3 476 1459 32666
Cache misses 0 - - -
Fast 1574286 230759864 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access22
Throttle count 0
Drops RP 92 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1497 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 530299 43932917 144421 48534450
Cache misses 0 - - -
Fast 0 4231873479 1920514 867790020
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1494 33387
Cache misses 0 - - -
Fast 1486754 216568229 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access23
Throttle count 0
Drops RP 854 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1574 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 360416 30451060 127860 22406985
Cache misses 0 - - -
Fast 0 4244722174 1455905 658293946
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1606 35302
Cache misses 0 - - -
Fast 1193016 169035291 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access24
Throttle count 0
Drops RP 791 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1383 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 635317 57176441 274789 38807987
Cache misses 0 - - -
Fast 0 4240263968 1744793 843422871
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1443 32431
Cache misses 0 - - -
Fast 1270949 186043589 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access25
Throttle count 0
Drops RP 437 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1472 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 506082 67320452 156645 53841382
Cache misses 0 - - -
Fast 0 4254844149 1336257 678969829
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1494 33075
Cache misses 0 - - -
Fast 943874 138834598 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access26
Throttle count 0
Drops RP 161 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1452 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 638487 61873711 250901 36291779
Cache misses 0 - - -
Fast 0 4243929285 1643409 874089024
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1448 32331
Cache misses 0 - - -
Fast 1208586 282820486 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access27
Throttle count 0
Drops RP 47 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1193 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 635701 57941025 225994 54350165
Cache misses 0 - - -
Fast 0 4209827791 2595644 1365201042
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1116 25016
Cache misses 0 - - -
Fast 1969977 298804000 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access28
Throttle count 0
Drops RP 574 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1307 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 485335 41782936 126960 31337554
Cache misses 0 - - -
Fast 0 4257164802 1359124 888448013
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1456 32426
Cache misses 0 - - -
Fast 880306 141359199 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access29
Throttle count 0
Drops RP 38 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1355 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 483136 48460745 163196 20491301
Cache misses 0 - - -
Fast 0 4238898808 1762724 814229453
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1289 28633
Cache misses 0 - - -
Fast 1340339 200034234 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access30
Throttle count 0
Drops RP 162 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1435 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 628336 47019811 152192 62523371
Cache misses 0 - - -
Fast 0 4241221039 1860314 887455892
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1380 30809
Cache misses 0 - - -
Fast 1267054 174862587 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access31
Throttle count 0
Drops RP 45 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1437 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 373685 25036296 95646 19564507
Cache misses 0 - - -
Fast 0 4253939375 1351340 673383157
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1417 31617
Cache misses 0 - - -
Fast 954337 131541481 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access32
Throttle count 0
Drops RP 6793 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1330 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 435531 42768430 148236 27659810
Cache misses 0 - - -
Fast 0 4224009720 1968803 1008932624
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 4 994 1273 28717
Cache misses 0 - - -
Fast 1650360 268041722 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access33
Throttle count 0
Drops RP 161 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1466 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 575600 44871140 75686 16228264
Cache misses 0 - - -
Fast 0 4248653238 1677023 714539541
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1521 34245
Cache misses 0 - - -
Fast 1076733 147373425 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access34
Throttle count 0
Drops RP 271 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1617 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 587310 54247232 166705 68518548
Cache misses 0 - - -
Fast 0 4236815741 1807142 792018975
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1628 36321
Cache misses 0 - - -
Fast 1370489 210548091 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access35
Throttle count 0
Drops RP 5411 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1355 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 609256 41104966 147257 32686347
Cache misses 0 - - -
Fast 0 4244950982 1805991 836144818
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1478 33157
Cache misses 0 - - -
Fast 1172783 173053677 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access36
Throttle count 0
Drops RP 113 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1184 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 364030 35722962 182967 84704499
Cache misses 0 - - -
Fast 0 4238070336 1644834 715974868
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 4 472 1170 25880
Cache misses 0 - - -
Fast 1333889 191278734 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access37
Throttle count 0
Drops RP 90 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1333 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 679437 61681771 254719 49482118
Cache misses 0 - - -
Fast 0 4235470033 1752570 984726797
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 1 44 1429 31658
Cache misses 0 - - -
Fast 1404500 186150965 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access38
Throttle count 0
Drops RP 533 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1371 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 464589 34816730 227534 43606592
Cache misses 0 - - -
Fast 0 4236394344 1728261 756767379
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1481 32884
Cache misses 0 - - -
Fast 1377625 175754505 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access39
Throttle count 0
Drops RP 27 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1486 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 720562 56215491 114289 42609960
Cache misses 0 - - -
Fast 0 4220834658 2163365 1122282330
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1454 32286
Cache misses 0 - - -
Fast 1786201 246258196 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access40
Throttle count 0
Drops RP 22 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1380 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 535544 41887890 125172 40967808
Cache misses 0 - - -
Fast 0 4257572089 1424508 618556788
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 3 202 1467 32790
Cache misses 0 - - -
Fast 885470 119187022 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access41
Throttle count 0
Drops RP 151 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1191 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 565251 54070904 133298 46374533
Cache misses 0 - - -
Fast 0 4225153603 2225791 1100060202
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1387 30905
Cache misses 0 - - -
Fast 1617955 208651068 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access42
Throttle count 0
Drops RP 2 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1250 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 501330 44178607 160943 40849634
Cache misses 0 - - -
Fast 0 4259891342 1165738 614335853
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1228 27094
Cache misses 0 - - -
Fast 819183 113108915 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access43
Throttle count 0
Drops RP 3550 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1256 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 512344 43143521 107030 20424904
Cache misses 0 - - -
Fast 0 4241023509 1728960 844364863
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1306 29592
Cache misses 0 - - -
Fast 1270811 180103975 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access44
Throttle count 0
Drops RP 712 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1201 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 318024 31629829 110646 17180763
Cache misses 0 - - -
Fast 0 4251315451 1339918 656597334
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1267 28062
Cache misses 0 - - -
Fast 1026586 142319017 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access45
Throttle count 0
Drops RP 11 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1439 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 494984 46696243 133850 31149504
Cache misses 0 - - -
Fast 0 4240864407 1760485 1040105221
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1520 33341
Cache misses 0 - - -
Fast 1249211 181229200 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access46
Throttle count 0
Drops RP 1510 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1135 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 671993 58945197 177154 35802601
Cache misses 0 - - -
Fast 0 4244644148 1614624 706468121
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1178 26088
Cache misses 0 - - -
Fast 1197244 150400390 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access47
Throttle count 0
Drops RP 1085 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1258 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 397738 42853254 108703 14396768
Cache misses 0 - - -
Fast 0 4246290363 1478684 670012862
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1314 29272
Cache misses 0 - - -
Fast 1160482 156314672 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access48
Throttle count 0
Drops RP 11 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1296 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 426041 50715678 85673 17980810
Cache misses 0 - - -
Fast 0 4258372163 1282269 672227834
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 8 966 1311 29021
Cache misses 0 - - -
Fast 849018 113508788 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access49
Throttle count 0
Drops RP 125 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1169 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 423680 37300261 156412 37607086
Cache misses 0 - - -
Fast 0 4264020738 949437 544026856
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1217 27213
Cache misses 0 - - -
Fast 736723 112199708 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access50
Throttle count 0
Drops RP 39 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1070 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 601705 47401766 130357 15962041
Cache misses 0 - - -
Fast 0 4256197585 1480598 650085061
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 2 497 1156 26192
Cache misses 0 - - -
Fast 907040 142669467 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access51
Throttle count 0
Drops RP 233 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1284 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 332419 29039208 88514 16711712
Cache misses 0 - - -
Fast 0 4258873350 1179038 708855668
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1267 28126
Cache misses 0 - - -
Fast 856043 117786229 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access52
Throttle count 0
Drops RP 36 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1145 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 651684 46139130 153675 68597390
Cache misses 0 - - -
Fast 0 4258328596 1465341 616075487
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1233 27689
Cache misses 0 - - -
Fast 869355 140421216 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access53
Throttle count 0
Drops RP 3335 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1201 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 601492 41818261 157694 19739262
Cache misses 0 - - -
Fast 0 4234328401 1984960 914638097
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1365 30050
Cache misses 0 - - -
Fast 1411974 257922581 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access54
Throttle count 0
Drops RP 269 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 1231 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 488694 45053065 111366 16810694
Cache misses 0 - - -
Fast 0 4253954373 1445099 701329870
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 1251 28176
Cache misses 0 - - -
Fast 989842 192707176 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access55
Throttle count 0
Drops RP 0 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 469 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 241527 22228499 34502 7320205
Cache misses 0 - - -
Fast 0 4284587788 461559 237671983
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 685 15210
Cache misses 0 - - -
Fast 243216 32938583 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access56
Throttle count 0
Drops RP 20 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 403 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 35820 2309500 18386 2965583
Cache misses 0 - - -
Fast 0 4278749323 399232 129812701
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 288 6588
Cache misses 0 - - -
Fast 383540 49595596 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access57
Throttle count 0
Drops RP 39 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 332 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 34591 2348280 22904 3339335
Cache misses 0 - - -
Fast 0 4282842047 309615 146884023
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 248 5386
Cache misses 0 - - -
Fast 287746 39337681 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access58
Throttle count 0
Drops RP 3 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 258 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 54592 3971588 54953 22415867
Cache misses 0 - - -
Fast 0 4285296631 262819 168321503
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 196 4431
Cache misses 0 - - -
Fast 225211 27264970 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Virtual-Access59
Throttle count 0
Drops RP 1178 SP 0
SPD Flushes Fast 0 SSE 0
SPD Aggress Fast 0
SPD Priority Inputs 304 Drops 0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 25887 1593980 13910 3941330
Cache misses 0 - - -
Fast 0 4289250729 173438 128822881
Auton/SSE 0 0 0 0Protocol Other
Switching path Pkts In Chars In Pkts Out Chars Out
Process 0 0 264 5862
Cache misses 0 - - -
Fast 132656 23003322 0 0
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Tunnel0Protocol IP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 5 300 16332 779640
Cache misses 0 - - -
Fast 0 0 78921 5640010
Auton/SSE 0 0 0 0NOTE: all counts are cumulative and reset only after a reload.
Protocol ARP
Switching path Pkts In Chars In Pkts Out Chars Out
Process 61179087 3671249886 4420186 300572648
Cache misses 0 - - -
Fast 0 0 0 0
Auton/SSE 0 0 0 0
У вас arp-флуд. На интерфейс пришло 3 гигабайта ARP-ов, циска от них ложится..
>У вас arp-флуд. На интерфейс пришло 3 гигабайта ARP-ов, циска от них
>ложится..
И как быть? Как с этим бороться?
>>У вас arp-флуд. На интерфейс пришло 3 гигабайта ARP-ов, циска от них
>>ложится..
>И как быть? Как с этим бороться?Мочить.
Насколько я понимаю, сейчас какой-то вирусняк появился, который работает подобным образом (шлет arp)..
>>>У вас arp-флуд. На интерфейс пришло 3 гигабайта ARP-ов, циска от них
>>>ложится..
>>И как быть? Как с этим бороться?
>
>Мочить.
>Насколько я понимаю, сейчас какой-то вирусняк появился, который работает подобным образом (шлет
>arp)..
Хорошо сказать... А вот как мочить, когда сеть на ~500 рабочих станций с динамической раздачей адресов?..
>У вас arp-флуд. На интерфейс пришло 3 гигабайта ARP-ов, циска от них
>ложится..
Я тут подумал, а ведь это показания суммарные с того момента как циска была последний раз включена. Она уже работает: rtr1-len1 uptime is 4 weeks, 6 days, 6 hours, 29 minutes, вот за это время и накопилось. Да конечно число для арпа большое. Однако в момент большой загрузки я не наблюдаю, что процессу ARP Input отведено много процессорного времени. Что вы думаете по этому поводу?
>>У вас arp-флуд. На интерфейс пришло 3 гигабайта ARP-ов, циска от них
>>ложится..
>Я тут подумал, а ведь это показания суммарные с того момента как
>циска была последний раз включена. Она уже работает: rtr1-len1 uptime is
>4 weeks, 6 days, 6 hours, 29 minutes, вот за это
>время и накопилось. Да конечно число для арпа большое. Однако в
>момент большой загрузки я не наблюдаю, что процессу ARP Input отведено
>много процессорного времени. Что вы думаете по этому поводу?
Все правильно, счетчики кумулятивные.
Однако arp input вылезает наверх с 2.07% процессорного времени, остальное занимают прерывания самой циски. Посмотрите, где этот процесс болтается во время нормальной работы.
>Все правильно, счетчики кумулятивные.
>Однако arp input вылезает наверх с 2.07% процессорного времени, остальное занимают прерывания
>самой циски. Посмотрите, где этот процесс болтается во время нормальной работы.Так все же, еще раз. Как защитить маршрутизатор от этого arp флуда. Я посмотрел по форуму, ничего на эту тему практически не нашел. Есть у вас какие-нибудь мысли?
Самое интересное, что в сети стоит куча серверов и коммутатор Cisco Catalyst 2924XL и у них такой проблемы нет.
>Самое интересное, что в сети стоит куча серверов и коммутатор Cisco Catalyst
>2924XL и у них такой проблемы нет.На них такой проблемы и не должно быть.
А вообще нужно вычислить mac-адрес того, кто шлет много arp-запросов. Например через tcpdump. А потом найти какой это порт на каталисте и принять меры.
>>Все правильно, счетчики кумулятивные.
>>Однако arp input вылезает наверх с 2.07% процессорного времени, остальное занимают прерывания
>>самой циски. Посмотрите, где этот процесс болтается во время нормальной работы.
>
>Так все же, еще раз. Как защитить маршрутизатор от этого arp флуда.
>Я посмотрел по форуму, ничего на эту тему практически не нашел.
>Есть у вас какие-нибудь мысли?
>Самое интересное, что в сети стоит куча серверов и коммутатор Cisco Catalyst
>2924XL и у них такой проблемы нет.
А вот 3750 укладывается.L2-коммутаторам пофиг, они арпы не обрабатывают..
>А вот 3750 укладывается.
>L2-коммутаторам пофиг, они арпы не обрабатывают..
Т.е., если я подключу маршрутизатор к 3750, то он его прикроет от этого арп напастия? У меня маршрутизатор подключен к транковому порту коммутатора.
>Т.е., если я подключу маршрутизатор к 3750, то он его прикроет от
>этого арп напастия? У меня маршрутизатор подключен к транковому порту коммутатора.
>Вы снифером найдёте негодяя и прикроете его банальным отключением или AL. Каталисты ко всему прочему поддерживают ограничение для бродкаст-трафика.
Товарищи, никак я не могу решить эту проблему.
Вот, наблюдаю опять картину перегрузки. Связь с маршрутизатором уже отсутствует минут 15, при этом снифером сервера, подключенного к этой же сети, я не наблюдаю большого arp flood'a. Это к выссказанной гипотезе о том, что его перегружает arp flood.
Коммутатор Catalyst 2924XL, к которому подключен этот маршрутизатор показывает следующюю загрузку CPU utilization for five seconds: 36%/9%; one minute: 33%; five minutes: 34%
Т.е. 9% на прерывания. Как же так получается, что маршрутизатор перегружен прерываниями?
Кто как думает?
>Товарищи, никак я не могу решить эту проблему.
>Вот, наблюдаю опять картину перегрузки. Связь с маршрутизатором уже отсутствует минут 15,
>при этом снифером сервера, подключенного к этой же сети, я не
>наблюдаю большого arp flood'a. Это к выссказанной гипотезе о том, что
>его перегружает arp flood.
>Коммутатор Catalyst 2924XL, к которому подключен этот маршрутизатор показывает следующюю загрузку CPU
>utilization for five seconds: 36%/9%; one minute: 33%; five minutes: 34%
>
>Т.е. 9% на прерывания. Как же так получается, что маршрутизатор перегружен прерываниями?
>
>Кто как думает?
Кстати, а на fa0/0 у вас ip нету или вы его вырезали просто? :-)
Конфиг циски покажите (не забудьте вырезать пароли).Сервер находится в том же сегменте, что и интерфейсы циски?
По поводу коммутатора - не понял, какая тут связь. Коммутатор обрабатывет процессором только cdp, stp, vtp и так далее. ARP-ы коммутатору пофигу, он их свитчит аппаратно.
>Кстати, а на fa0/0 у вас ip нету или вы его вырезали
>просто? :-)
Этому интерфейсу адрес не назначен. У меня всего один порт и он транковый.
>Сервер находится в том же сегменте, что и интерфейсы циски?
Да, в том же.
>
>По поводу коммутатора - не понял, какая тут связь. Коммутатор обрабатывет процессором
>только cdp, stp, vtp и так далее. ARP-ы коммутатору пофигу, он
>их свитчит аппаратно.
Понятно. Я просто стараюсь как можно информации предоставить.
Вот конфиг маршрутизатора.
Building configuration...Current configuration : 12035 bytes
!
! Last configuration change at 18:22:32 MSD Sun Oct 15 2006 by monty
! NVRAM config last updated at 18:22:35 MSD Sun Oct 15 2006 by monty
!
version 12.3
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime localtime
service timestamps log datetime localtime
service password-encryption
!
hostname rtr1-len1
!
boot-start-marker
boot-end-marker
!
logging buffered 4096 debugging
no logging console
enable secret 5 [cut]
!
clock timezone MSK 3
clock summer-time MSD recurring last Sun Mar 2:00 last Sun Oct 2:00
aaa new-model
!
!
aaa authentication login default local
aaa authentication ppp default group radius
aaa authorization exec default local
aaa authorization network default group radius
aaa accounting delay-start
aaa accounting update newinfo periodic 1
aaa accounting network default start-stop group radius
aaa session-id common
ip subnet-zero
no ip source-route
no ip rcmd domain-lookup
ip rcmd rcp-enable
ip rcmd rsh-enable
ip rcmd remote-host cwuser 192.168.111.45 cwuser enable
ip rcmd remote-host cwuser 192.168.111.45 Ed enable
ip rcmd remote-host vpnkill 62.33.232.205 root enable
ip rcmd remote-username cwuser
ip tcp selective-ack
ip tcp timestamp
ip cef
!
!
ip domain name mannet.lan
ip name-server [cut]
no ip dhcp conflict logging
ip dhcp excluded-address 10.30.0.1 10.30.0.255
!
ip dhcp pool Net-31
network 10.31.0.0 255.255.0.0
domain-name mannet.lan
netbios-name-server 10.31.0.2
netbios-node-type h-node
default-router 10.31.0.2
lease 0 0 1
!
ip dhcp pool Net-32
network 10.32.0.0 255.255.0.0
domain-name mannet.lan
netbios-name-server 10.31.0.2
netbios-node-type h-node
default-router 10.32.0.2
lease 0 0 1
!
ip dhcp pool Net-37
network 10.37.0.0 255.255.0.0
domain-name mannet.lan
netbios-name-server 10.37.0.2
netbios-node-type h-node
default-router 10.37.0.2
dns-server 10.37.0.251
!
ip dhcp pool Net-33
network 10.33.0.0 255.255.0.0
netbios-name-server 10.33.0.2
default-router 10.33.0.2
dns-server 10.33.0.251
netbios-node-type h-node
lease 0 23 59
!
ip dhcp pool Net-34
network 10.34.0.0 255.255.0.0
netbios-name-server 10.34.0.2
default-router 10.34.0.2
dns-server 10.34.0.251
netbios-node-type h-node
lease 0 23 59
!
ip dhcp pool Net-38
network 10.38.0.0 255.255.0.0
domain-name mannet.lan
dns-server 10.38.0.251
lease 0 23 59
!
no ip bootp server
ip audit po max-events 100
vpdn enable
vpdn logging
vpdn logging remote
vpdn session-limit 100
vpdn ip udp ignore checksum
!
vpdn-group 1
! Default PPTP VPDN group
accept-dialin
protocol pptp
virtual-template 1
session-limit 32767
!
!
!
!
!
!
!
!
!
!
!
!
!
username vpnkill privilege 15 secret 5 [cut]
!
!
!
!
!
!
interface Tunnel0
ip address 192.168.200.1 255.255.255.252
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
tunnel source [cut]
tunnel destination [cut]
!
interface FastEthernet0/0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
duplex auto
speed auto
!
interface FastEthernet0/0.1
encapsulation isl 10
ip address 192.168.111.6 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
no snmp trap link-status
!
interface FastEthernet0/0.2
encapsulation isl 20
ip address 10.100.111.6 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat inside
no snmp trap link-status
!
interface FastEthernet0/0.3
description satellite
encapsulation isl 7
ip address 10.100.0.2 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
no snmp trap link-status
no cdp enable
!
interface FastEthernet0/0.4
encapsulation isl 38
ip address 10.38.0.2 255.255.0.0
ip access-group 138 in
no ip redirects
no ip unreachables
no ip proxy-arp
no snmp trap link-status
no cdp enable
!
interface FastEthernet0/0.5
description Net-2
encapsulation isl 40
ip address 10.30.0.2 255.255.0.0
ip access-group 120 in
ip helper-address 10.30.0.8
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting output-packets
ip accounting precedence input
ip accounting access-violations
ip nat inside
no snmp trap link-status
!
interface FastEthernet0/0.6
encapsulation isl 5
ip address 10.0.99.26 255.255.255.252 secondary
ip address [cut] 255.255.255.248
ip access-group 100 in
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting precedence input
ip accounting access-violations
ip nat outside
no snmp trap link-status
traffic-shape group 101 1000000 125000 125000 1000
no cdp enable
!
interface FastEthernet0/0.7
encapsulation isl 37
ip address 10.37.0.2 255.255.0.0
ip access-group 135 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
no snmp trap link-status
no cdp enable
!
interface FastEthernet0/0.8
encapsulation isl 33
ip address 10.33.0.2 255.255.0.0
ip access-group 121 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
no snmp trap link-status
no cdp enable
!
interface FastEthernet0/0.9
encapsulation isl 22
ip address 10.22.0.2 255.255.0.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
no snmp trap link-status
no cdp enable
!
interface FastEthernet0/0.10
encapsulation isl 34
ip address 10.34.0.2 255.255.0.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
no snmp trap link-status
no cdp enable
!
interface FastEthernet0/0.11
encapsulation isl 31
ip address 10.31.0.2 255.255.0.0
ip access-group 136 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
no snmp trap link-status
no cdp enable
!
interface Virtual-Template1
ip unnumbered FastEthernet0/0.6
ip access-group 150 in
no ip proxy-arp
ip accounting access-violations
ip nat inside
ip tcp header-compression
ip mroute-cache
no peer default ip address
no keepalive
ppp authentication pap chap ms-chap ms-chap-v2
ppp ipcp dns 80.237.8.251
!
ip nat inside source list 3 interface FastEthernet0/0.6 overload
no ip http server
no ip http secure-server
ip classless
ip route 0.0.0.0 0.0.0.0 [cut]
ip route 10.10.0.0 255.255.0.0 Tunnel0
ip route 10.20.0.0 255.255.0.0 10.30.0.5
ip route 10.36.0.0 255.255.0.0 [cut]
!
!
logging trap debugging
logging facility local0
logging source-interface FastEthernet0/0.6
logging [cut]
access-list 3 permit 192.168.30.0 0.0.0.255
access-list 3 permit 192.168.37.0 0.0.0.255
access-list 3 permit 192.168.33.0 0.0.0.255
access-list 3 permit 192.168.20.0 0.0.0.255
access-list 100 deny icmp any any redirect
access-list 100 permit ip any any
access-list 101 permit udp any any
access-list 110 permit tcp 10.31.0.0 0.0.255.255 10.30.0.0 0.0.255.255
access-list 110 permit tcp 10.31.0.0 0.0.255.255 10.32.0.0 0.0.255.255
access-list 110 permit udp 10.31.0.0 0.0.255.255 10.30.0.0 0.0.255.255
access-list 110 permit udp 10.31.0.0 0.0.255.255 10.32.0.0 0.0.255.255
access-list 110 permit tcp 10.31.0.0 0.0.255.255 [cut]
access-list 110 permit tcp host 10.31.0.4 host 10.31.0.2 eq telnet
access-list 110 permit tcp 10.31.0.0 0.0.255.255 host 10.31.0.2 eq 1723
access-list 110 permit gre 10.31.0.0 0.0.255.255 host 10.31.0.2
access-list 110 permit tcp 10.31.0.0 0.0.255.255 host 10.31.0.2 eq domain
access-list 110 permit udp 10.31.0.0 0.0.255.255 host 10.31.0.2 eq domain
access-list 110 permit udp 10.31.0.0 0.0.255.255 host 10.31.0.2 eq bootps
access-list 120 permit gre 10.30.0.0 0.0.255.255 host 10.30.0.2
access-list 120 permit tcp 10.30.0.0 0.0.255.255 host 10.30.0.2 eq 1723
access-list 120 permit tcp 10.30.0.0 0.0.255.255 host [cut] eq www
access-list 120 permit tcp 10.30.0.0 0.0.255.255 host [cut] eq www
access-list 120 permit tcp 10.30.0.0 0.0.255.255 host [cut] eq 443
access-list 120 permit tcp 10.30.0.0 0.0.255.255 host [cut] eq smtp
access-list 120 permit tcp 10.30.0.0 0.0.255.255 host [cut] eq pop3
access-list 120 permit tcp 10.30.0.0 0.0.255.255 host [cut] eq 6667
access-list 120 permit tcp host 10.30.0.3 eq telnet [cut] log
access-list 120 permit icmp any any
access-list 120 permit ip host 10.30.0.5 [cut]
access-list 120 permit tcp 10.20.0.0 0.0.255.255 [cut]
access-list 120 permit ip host 10.30.0.5 any
access-list 120 permit ip host 10.30.0.7 any
access-list 121 permit tcp 10.33.0.0 0.0.255.255 [cut]
access-list 121 permit tcp 10.33.0.0 0.0.255.255 host 10.33.0.2 eq 1723
access-list 121 permit gre 10.33.0.0 0.0.255.255 host 10.33.0.2
access-list 121 permit tcp 10.33.0.0 0.0.255.255 host 10.33.0.2 eq domain
access-list 121 permit udp 10.33.0.0 0.0.255.255 host 10.33.0.2 eq domain
access-list 121 permit icmp any any
access-list 121 permit udp any any eq bootpc
access-list 121 permit udp any any eq bootps
access-list 135 permit tcp 10.37.0.0 0.0.255.255 10.36.0.0 0.0.255.255
access-list 135 permit udp 10.37.0.0 0.0.255.255 10.36.0.0 0.0.255.255
access-list 135 permit tcp 10.37.0.0 0.0.255.255 [cut]
access-list 135 permit tcp host 10.37.0.4 host 10.37.0.2 eq telnet
access-list 135 permit tcp 10.37.0.0 0.0.255.255 host 10.37.0.2 eq 1723
access-list 135 permit gre 10.37.0.0 0.0.255.255 host 10.37.0.2
access-list 135 permit tcp 10.37.0.0 0.0.255.255 host 10.37.0.2 eq domain
access-list 135 permit udp 10.37.0.0 0.0.255.255 host 10.37.0.2 eq domain
access-list 135 permit icmp any any
access-list 135 permit udp any any eq bootpc
access-list 135 permit udp any any eq bootps
access-list 136 permit tcp 10.31.0.0 0.0.255.255 [cut]
access-list 136 permit tcp 10.31.0.0 0.0.255.255 host 10.31.0.2 eq 1723
access-list 136 permit gre 10.31.0.0 0.0.255.255 host 10.31.0.2
access-list 136 permit tcp 10.31.0.0 0.0.255.255 host 10.31.0.2 eq domain
access-list 136 permit udp 10.31.0.0 0.0.255.255 host 10.31.0.2 eq domain
access-list 136 permit icmp any any
access-list 136 permit udp any any eq bootpc
access-list 136 permit udp any any eq bootps
access-list 136 permit tcp host 10.31.0.3 host 10.31.0.2 eq telnet
access-list 138 permit tcp 10.38.0.0 0.0.255.255 [cut]
access-list 138 permit tcp 10.38.0.0 0.0.255.255 host 10.38.0.2 eq 1723
access-list 138 permit gre 10.38.0.0 0.0.255.255 host 10.38.0.2
access-list 138 permit tcp 10.38.0.0 0.0.255.255 host 10.38.0.2 eq domain
access-list 138 permit udp 10.38.0.0 0.0.255.255 host 10.38.0.2 eq domain
access-list 138 permit icmp any any
access-list 138 permit udp any any eq bootpc
access-list 138 permit udp any any eq bootps
access-list 150 deny tcp any any range 135 139
access-list 150 deny tcp any any eq 445
access-list 150 deny udp any any range 135 netbios-ss
access-list 150 deny udp any any eq tftp
access-list 150 deny udp any any eq snmp
access-list 150 permit tcp any any
access-list 150 permit udp any any
access-list 150 permit icmp any any
access-list 150 permit ip any any
!
snmp-server community mysnmp RO
radius-server configure-nas
radius-server host [cut] auth-port 1812 acct-port 1813
radius-server retransmit 0
radius-server timeout 3
radius-server key 7 [cut]
!
!
!
!
!
line con 0
password 7 [cut]
line aux 0
line vty 0 4
password 7 [cut]
transport input ssh
!
ntp clock-period 17179721
ntp peer [cut]
!
end
Ничего подозрительно не видно? Какие у вас мысли есть по этому поводу еще?