-
مشکل cpu load در AS5300
سلام
من کانفیگ روتر رو در زیر آوردم. اگه اشکالی می بینید یه لطفی کنید راهنمایی کنید. وقتی تعداد کاربران زیاد می شود cpu load به بالای هشتاد درصد می رسد. حتی به 95 درصد هم می رسد. تعداد کاربران در حالت حداکثری 237 می شود.
[SIZE=2]service password-encryption[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]hostname AS3-PRI[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]boot-start-marker[/SIZE]
[SIZE=2]boot-end-marker[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]no logging console[/SIZE]
[SIZE=2]enable secret 5 $1$dZNv$NtgIfV0.cbfw/VD8jZeg91[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]spe 1/0 2/9[/SIZE]
[SIZE=2] firmware location system:/ucode/mica_port_firmware[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]resource-pool disable[/SIZE]
[SIZE=2]clock timezone IRST 3 30[/SIZE]
[SIZE=2]clock summer-time IRDT date Mar 21 2009 0:00 Sep 22 2020 23:59[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]aaa new-model[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]aaa authentication login default local[/SIZE]
[SIZE=2]aaa authentication ppp default local group radius[/SIZE]
[SIZE=2]aaa authorization network default local group radius if-authenticated [/SIZE]
[SIZE=2]aaa accounting delay-start [/SIZE]
[SIZE=2]aaa accounting suppress null-username[/SIZE]
[SIZE=2]aaa accounting update newinfo periodic 1[/SIZE]
[SIZE=2]aaa accounting network default start-stop group radius[/SIZE]
[SIZE=2]aaa pod server auth-type any ignore server-key[/SIZE]
[SIZE=2]aaa session-id common[/SIZE]
[SIZE=2]ip subnet-zero[/SIZE]
[SIZE=2]ip rcmd rsh-enable[/SIZE]
[SIZE=2]ip rcmd remote-host root x.x.x.x root enable[/SIZE]
[SIZE=2]ip rcmd remote-host root x.x.x.x root enable[/SIZE]
[SIZE=2]ip rcmd remote-host root x.x.x.x root enable[/SIZE]
[SIZE=2]ip cef[/SIZE]
[SIZE=2]ip name-server x.x.x.x[/SIZE]
[SIZE=2]ip name-server x.x.x.x[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]async-bootp dns-server x.x.x.x x.x.x.x[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]isdn switch-type primary-net5[/SIZE]
[SIZE=2]modemcap entry mica-e1:MSC=&F&D2S34=18000S40=10S54=172S53=1S29=12S63=5[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]username xxxxxxxxxx privilege 15 password 7 xxxxxxxxxxxxxxxxxxxxxxxxxxxx[/SIZE]
[SIZE=2]username xxxxxxxxx privilege 15 password 7 xxxxxxxxxxxxxx[/SIZE]
[SIZE=2]username xxxxxxx privilege 15 password 7 xxxxxxxxxxxxxxxx[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]controller E1 0
framing NO-CRC4
clock source line primary
pri-group timeslots 1-31
!
controller E1 1
framing NO-CRC4
clock source line secondary 1
pri-group timeslots 1-31
!
controller E1 2
framing NO-CRC4
clock source line secondary 2
pri-group timeslots 1-31
!
controller E1 3
framing NO-CRC4
clock source line secondary 3
pri-group timeslots 1-31
!
controller E1 4
framing NO-CRC4
clock source line secondary 4
pri-group timeslots 1-31
!
controller E1 5
framing NO-CRC4
clock source line secondary 5
pri-group timeslots 1-31
!
controller E1 6
framing NO-CRC4
clock source line secondary 6
pri-group timeslots 1-31
!
controller E1 7
framing NO-CRC4
clock source line secondary 7
pri-group timeslots 1-31
!
!
interface Ethernet0
no ip address
shutdown
!
interface Serial0
no ip address
shutdown
clock rate 2015232
no fair-queue
!
interface Serial1
no ip address
shutdown
clock rate 2015232
no fair-queue
!
interface Serial2
no ip address
shutdown
clock rate 2015232
no fair-queue
!
interface Serial3
no ip address
shutdown
clock rate 2015232
no fair-queue
!
interface Serial0:15
ip unnumbered FastEthernet0
encapsulation ppp
isdn switch-type primary-net5
isdn incoming-voice modem
no peer default ip address
!
interface Serial1:15
ip unnumbered FastEthernet0
encapsulation ppp
isdn switch-type primary-net5
isdn incoming-voice modem
no peer default ip address
!
interface Serial2:15
ip unnumbered FastEthernet0
encapsulation ppp
isdn switch-type primary-net5
isdn incoming-voice modem
no peer default ip address
!
interface Serial3:15
ip unnumbered FastEthernet0
encapsulation ppp
isdn switch-type primary-net5
isdn incoming-voice modem
no peer default ip address
!
interface Serial4:15
ip unnumbered FastEthernet0
encapsulation ppp
isdn switch-type primary-net5
isdn incoming-voice modem
no peer default ip address
!
interface Serial5:15
ip unnumbered FastEthernet0
encapsulation ppp
isdn switch-type primary-net5
isdn incoming-voice modem
no peer default ip address
!
interface Serial6:15
ip unnumbered FastEthernet0
encapsulation ppp
isdn switch-type primary-net5
isdn incoming-voice modem
no peer default ip address
!
interface Serial7:15
ip unnumbered FastEthernet0
encapsulation ppp
isdn switch-type primary-net5
isdn incoming-voice modem
no peer default ip address
![/SIZE][SIZE=2] [/SIZE] [SIZE=2]interface FastEthernet0[/SIZE]
[SIZE=2] ip address x.x.x.x x.x.x.x[/SIZE]
[SIZE=2] duplex full[/SIZE]
[SIZE=2] speed 100[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]interface Group-Async0
ip unnumbered FastEthernet0
ip access-group anti in
ip access-group anti out
no ip unreachables
encapsulation ppp
ip tcp header-compression
no ip mroute-cache
ip policy route-map proxy-redirect
async mode interactive
peer default ip address pool POOL240
ppp authentication pap chap ms-chap callin
group-range 1 240
![/SIZE][SIZE=2][/SIZE] [SIZE=2]ip local pool POOL240 x.x.x.x x.x.x.x[/SIZE]
[SIZE=2]ip classless[/SIZE]
[SIZE=2]ip route 0.0.0.0 0.0.0.0 x.x.x.x[/SIZE]
[SIZE=2]no ip http server[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]ip access-list extended anti[/SIZE]
[SIZE=2]deny tcp any any range 133 139[/SIZE]
[SIZE=2] deny udp any any range 133 netbios-ss[/SIZE]
[SIZE=2] deny udp any any eq 370[/SIZE]
[SIZE=2] deny tcp any any eq 445[/SIZE]
[SIZE=2] deny tcp any any eq 593[/SIZE]
[SIZE=2] deny tcp any any eq 707[/SIZE]
[SIZE=2] deny udp any any range 995 999[/SIZE]
[SIZE=2] deny tcp any any range 1023 1025[/SIZE]
[SIZE=2] deny tcp any any eq 1214[/SIZE]
[SIZE=2] deny tcp any any eq 4751[/SIZE]
[SIZE=2] deny tcp any any eq 5554[/SIZE]
[SIZE=2] deny tcp any any eq 31337[/SIZE]
[SIZE=2] deny tcp any any eq 6667[/SIZE]
[SIZE=2] deny tcp any any eq 6346[/SIZE]
[SIZE=2] deny tcp any any eq 1034[/SIZE]
[SIZE=2] deny tcp any any eq 3140[/SIZE]
[SIZE=2] deny tcp any any eq 3410[/SIZE]
[SIZE=2] deny tcp any any eq 4191[/SIZE]
[SIZE=2] deny tcp any any eq 9136[/SIZE]
[SIZE=2] deny tcp any any eq 9898[/SIZE]
[SIZE=2] permit ip any any[/SIZE]
[SIZE=2]ip access-list extended as-anti[/SIZE]
[SIZE=2] deny udp any any eq tftp[/SIZE]
[SIZE=2] deny tcp any any range 133 139[/SIZE]
[SIZE=2] deny udp any any range 133 netbios-ss[/SIZE]
[SIZE=2] deny udp any any eq 370[/SIZE]
[SIZE=2] deny tcp any any eq 445[/SIZE]
[SIZE=2] deny tcp any any eq 593[/SIZE]
[SIZE=2] deny tcp any any eq 707[/SIZE]
[SIZE=2] deny udp any any range 995 999[/SIZE]
[SIZE=2] deny tcp any any range 1023 1025[/SIZE]
[SIZE=2] deny tcp any any eq 1214[/SIZE]
[SIZE=2] deny tcp any any eq 1234[/SIZE]
[SIZE=2] deny tcp any any eq 1549[/SIZE]
[SIZE=2] deny tcp any any eq 2535[/SIZE]
[SIZE=2] deny tcp any any eq 2745[/SIZE]
[SIZE=2] deny tcp any any range 3127 3129[/SIZE]
[SIZE=2] deny tcp any any eq 3333[/SIZE]
[SIZE=2] deny tcp any any eq 4444[/SIZE]
[SIZE=2] deny tcp any any eq 4751[/SIZE]
[SIZE=2] deny tcp any any eq 5554[/SIZE]
[SIZE=2] deny tcp any any eq 31337[/SIZE]
[SIZE=2] deny tcp any any eq 6667[/SIZE]
[SIZE=2] deny tcp any any eq 6346[/SIZE]
[SIZE=2] deny tcp any any eq 1034[/SIZE]
[SIZE=2] deny tcp any any eq 3140[/SIZE]
[SIZE=2] deny tcp any any eq 3410[/SIZE]
[SIZE=2] deny tcp any any eq 4191[/SIZE]
[SIZE=2] deny tcp any any eq 9136[/SIZE]
[SIZE=2] deny tcp any any eq 9898[/SIZE]
[SIZE=2] deny ip any 10.0.0.0 0.255.255.255[/SIZE]
[SIZE=2] deny ip any 172.20.0.0 0.0.255.255[/SIZE]
[SIZE=2] permit ip any any[/SIZE]
[SIZE=2]access-list 2 permit 172.20.20.12[/SIZE]
[SIZE=2]access-list 2 permit 172.20.20.4[/SIZE]
[SIZE=2]access-list 2 permit 172.20.20.25[/SIZE]
[SIZE=2]access-list 2 permit x.x.x.0 0.0.0.7[/SIZE]
[SIZE=2]access-list 2 permit x.x.x.x 0.0.0.7[/SIZE]
[SIZE=2]access-list 2 permit x.x.x.x 0.0.0.7[/SIZE]
[SIZE=2]access-list 2 permit x.x.x.x 0.0.0.7[/SIZE]
[SIZE=2]access-list 2 permit x.x.x.x 0.0.0.7[/SIZE]
[SIZE=2]access-list 2 permit x.x.x.x 0.0.0.7[/SIZE]
[SIZE=2]access-list 2 permit x.x.x.x 0.0.0.15[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]tftp-server flash:c5300-is-mz.123-20.bin[/SIZE]
[SIZE=2]snmp-server community xxxx RO 2[/SIZE]
[SIZE=2]snmp-server community xxxx xxx 1[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]radius-server attribute 44 include-in-access-req[/SIZE]
[SIZE=2]radius-server attribute 32 include-in-access-req [/SIZE]
[SIZE=2]radius-server host x.x.x.x auth-port 1812 acct-port xxxxkey 7 xxxxxx[/SIZE]
[SIZE=2]radius-server key 7 xxxxxxxxx
[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]line con 0[/SIZE]
[SIZE=2] password 7 0107030C490A08[/SIZE]
[SIZE=2] logging synchronous[/SIZE]
[SIZE=2]line 1 120[/SIZE]
[SIZE=2] no flush-at-activation[/SIZE]
[SIZE=2] modem Dialin[/SIZE]
[SIZE=2] modem autoconfigure type mica-e1[/SIZE]
[SIZE=2] autocommand ppp[/SIZE]
[SIZE=2] transport preferred none[/SIZE]
[SIZE=2] transport input all[/SIZE]
[SIZE=2] transport output none[/SIZE]
[SIZE=2] autoselect ppp[/SIZE]
[SIZE=2]line aux 0[/SIZE]
[SIZE=2] modem autoconfigure type mica-e1[/SIZE]
[SIZE=2] autocommand ppp[/SIZE]
[SIZE=2] transport preferred none[/SIZE]
[SIZE=2] transport input all[/SIZE]
[SIZE=2] transport output none[/SIZE]
[SIZE=2] autoselect ppp[/SIZE]
[SIZE=2]line vty 0 4[/SIZE]
[SIZE=2] session-timeout 30 [/SIZE]
[SIZE=2] password 7 xxxxxxxxxxx[/SIZE]
[SIZE=2] transport preferred none[/SIZE]
[SIZE=2] transport input pad telnet rlogin udptn[/SIZE]
[SIZE=2] transport output none[/SIZE]
[SIZE=2]line vty 5 15[/SIZE]
[SIZE=2] password 7 xxxxxxxxxxxx[/SIZE]
[SIZE=2] transport preferred none[/SIZE]
[SIZE=2] transport input pad telnet rlogin udptn[/SIZE]
[SIZE=2] transport output none[/SIZE]
[SIZE=2]![/SIZE]
[SIZE=2]ntp clock-period 17179781[/SIZE]
[SIZE=2]ntp server 192.43.244.18[/SIZE]
[SIZE=2]end[/SIZE]