I agree I need to optimize them and do somehing because it is reaching its max before the CPU starts processing them but I am not certain this is what is When the next command, debug platform cpu-queue icmp-q, was entered, the flood began. When I got there and started doing some show commands I saw that it had almost 100% CPU for more than 3 days!

One of those access switchs had 26000 packet/sec on it's uplink and after the reload it dropped to 50! Version 15.0(1)SE3.

A rapidly incrementing packet type indicates that packet type is flooding the IP stack. Wiresharks shows that 100s of computers are flooding the network with ARP Broadcast ...

See the “Analyzing Network Traffic” section for investigation information. This normally happens one of two ways. A complete or partial SNMP MIB walk. Cat4k Mgmt Lopri High Cpu You can enter the show platform ip unicast counts privileged EXEC command to see how many of these routes were not properly programmed into the TCAM.

Note:The switch reload is required to use the new SDM template. Cisco Router High Cpu Interrupts EtherChannel links bounce—When the network device at the other end of the EtherChannel does not receive the protocol packets required to maintain the EtherChannel link, this might bring down the link. See Catalyst 3750 Series Switches High CPU Utilization Troubleshooting. https://supportforums.cisco.com/discussion/11532116/high-cpu-usage-3750-x-stack Do not use wake-up proxy if your network monitoring tools and services do not allow MAC flaps.

share|improve this answer answered Oct 29 '13 at 13:29 DoxTheFox interesting story... Show Tcam Utilization 6500 Seriously! - Süre: 1:45:33. That is like 20 Meg at 64 packet size. See More 1 2 3 4 5 Overall Rating: 0 (0 ratings) Log in or register to post comments Leo Laohoo Mon, 10/28/2013 - 21:27 I'm not totally sure what's going

Enter the show sdm prefer privileged EXEC command to see the active SDM template on a switch: Switch# show sdm prefer The current template is "desktop default" template. https://community.spiceworks.com/topic/559140-cisco-3750-high-cpu-utilization my snmp surv would report CPU usage of 100% on a certain switch. Hulc Led Process High Cpu The switch counts every IP packet that the hardware punts to the CPU for IP routing. How To Check Bandwidth Utilization On Cisco Router The switch typically receives SNMP queries at regular intervals, and the SNMP Engine system process consumes CPU resources handling the queries.

Enter the show platform port-asic stats drop privileged EXEC command to see the CPU receive-queue discard counts and to identify the queue discarding packets. navigate here Refer to Specifying a Next Hop IP Address for Static Routes for more information on how to configure the next hop IP address for static routing. Thanks! 28 commentsshareall 28 commentssorted by: besttopnewcontroversialoldrandomq&alive (beta)[–]boondock_ 2 points3 points4 points 2 years ago(1 child)I ran into an issue over the summer with a 3 switch stack running at 100% CPU for no Be ready to enter the undebug all privileged EXEC command to stop any packet flooding on the console. Ip Input High Cpu

Enter the command several times to see if the counts for sw forwarding are rapidly incrementing. Show Memory Usage Cisco The CPU usage is normally high in these situations. You enable summary routes on peer routers.

The switch will never report CPU utilization at 0%.

His core competency lies in areas of penetration testing, security assessments, enterprise network design, capacity planning and vendor evaluation. When a particular count is incrementing rapidly, the IP packet type is probably flooding the CPU. The manager computer also sends ARP packets for the sleeping computers to keep the entry fresh in the ARP cache. Ip Input High Cpu Cisco 3750 In the stacked switch, the CPU utilization is measured on the master switch only.

In order to use PBR, you must first enable the routing template with the sdm prefer routing global configuration command. I have reviewed configurations and IOS Change logs, and have been working with Cisco's TAC. New Cheap WiFi setup New configurable routing through what was already setup TECHNOLOGY IN THIS DISCUSSION Cisco 346471 Followers Follow Cisco Cisco Network Assistant Join the Community! this contact form Queue 15 corresponds to cpu heartbeat, and so on.

permalinkembedsaveparentgive gold[–]SgoudreaultPacket Ninja 1 point2 points3 points 2 years ago(0 children)Something else to look for would be the same mac address living in two different vlans. You can pull statistics from SNMP with very limited resources required from the stack.I have disabled the http but not secure http. 0 Jalapeno OP Tdawg1982 Aug 12, Punted packets are handled at the interrupt level and can cause the CPU to become too busy. See the “Monitoring IP Traffic Counts” section.

We use Cisco TAC said they don't see anything wrong with using /20, other then we'd have a large broadcast domain but should still function. Then, it sends to all the switches in the stack. These values are typical for a nonstacked switch in a small and stable environment. A high interrupt percentage indicates too much network traffic.

Switch# show processes cpu sorted 5sec CPU utilization for five seconds: 53%/28%; one minute: 48%; five minutes: 45% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 78 461805 220334990 2 However, a capacity issue is almost never a symptom of high CPU utilization with hardware-based forwarding switches. Yükleniyor... Before you start debugging the receive queues, use this procedure to prevent other applications from writing to the console, to increase the system log buffer (if it is at the default

Issue the show platform tcam utilization command to see how much TCAM has now been utilized and how much is available. show ip route summary Shows the number of route entries used by each protocol. Cisco Support Community 3.920 görüntüleme 1:06:55 Live Webcast:Configure and Troubleshoot Wired and Wireless Networks Using Cisco Prime Infrastructure - Süre: 1:32:14. Nothing suspicious!

The MAC addresses also exist on other interfaces, which would explain large number of MAC flaps @RickyBeam i agree with why hosts are sending so many ARP requests; this is one Switch# show ip traffic IP statistics: Rcvd: 12420483 total, 840467 local destination 0 format errors, 0 checksum errors, 0 bad hop count 0 unknown protocol, 222764 not a gateway 0 security The CPU can receive multiple packet types and have multiple active system processes. Ran show mac address-table on different switches and core itself (on the core, for example, plugged by desktop directly, my desktop ), and we can see the several different MAC hardware

This is just one example of a possible root cause for high CPU utilization.