Solved

Cisco Router Latency

Posted on 2009-04-02
6
1,189 Views
Last Modified: 2012-05-06
I'm noticing latency on one of my inbound connections.  The circuit is a DS3 provided by Verizon and it has a Cisco 3800 series router (managed by my company).  

My external clients connect to the home office via a Citrix Access Gateway (SSL VPN) and 70% of our traffic is HTTPS, I'm wondering if it would be in my best interest to place an inbound QOS for the following protocols:

443 - HTTPS
2598 - Citrix Session Relaiblity
1494 - Citrix ICA

If so, how would I go about enabling this on my device?  

Config listed below:
Building configuration...


Current configuration : 3726 bytes
!
! Last configuration change at 11:11:09 PCTime Thu Apr 2 2009 by r00t
! NVRAM config last updated at 10:24:55 PCTime Thu Apr 2 2009 by r00t
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname u257905
!
boot-start-marker
boot-end-marker
!
card type t3 1
security authentication failure rate 3 log
no logging buffered
enable secret 5 **********************
!
no aaa new-model
clock timezone PCTime -5
clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00
dot11 syslog
!
!
ip cef
!
!
no ip domain lookup
ip name-server 198.6.1.5
ip name-server 198.6.1.4
ip name-server 198.6.1.2
frame-relay switching
multilink bundle-name authenticated
!
voice-card 0
 no dspfarm
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
crypto pki trustpoint TP-self-signed-1918427529
 enrollment selfsigned
 subject-name cn=IOS-Self-Signed-Certificate-1918427529
 revocation-check none
 rsakeypair TP-self-signed-1918427529
!
!
crypto pki certificate chain TP-self-signed-1918427529
 certificate self-signed 01
  3082023F 308201A8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
  69666963 6174652D 31393138 34323735 3239301E 170D3039 30333330 31343331
  30355A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 39313834
  32373532 3930819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
  8100B038 7CD5998B 807318A5 0185BFF1 FB3086C5 AC8F303B BE994663 C792B7D4
  26A693E8 47C9CF3F CAF65835 52DD5FAE A69BA4F7 AEF94576 8CA10D42 F18426E9
  C42572F1 FA2A3CB5 AB0C7023 265CF46D 983A9B92 26C6E537 E9A0D9B9 3B8378A0
  2B05FC3F 888283CE 9472B735 E16D8F2B C054277A E2F4A9D6 C42E0CB2 1FC1D521
  FC130203 010001A3 67306530 0F060355 1D130101 FF040530 030101FF 30120603
  551D1104 0B300982 07753235 37393035 301F0603 551D2304 18301680 140C58F4
  B6416F0E E44D6A1A C6EE5974 0DC9AE9B C2301D06 03551D0E 04160414 0C58F4B6
  416F0EE4 4D6A1AC6 EE59740D C9AE9BC2 300D0609 2A864886 F70D0101 04050003
  81810007 7722F684 6FBA5A1C F42E4E8A 26693EDF 73D67CDB F85DE778 390DB035
  934E603B D65ACA4A FF922865 7B258E4A 1557E422 2A078BE9 FAA93EB4 F790B252
  6D1311AA 054509B8 6640DD58 7D919D2D 14AED0E7 8A0EA9EA B8B3D791 D6AF176D
  7193046B C378B49D C74707C8 994DA172 86BF969C CCAE8722 656C45AB 74EB770A F9EB00
        quit
!
!
username r00t privilege 15 password 7 **********************
archive
 log config
  hidekeys
!
!
controller T3 1/0
 clock source line
 cablelength 10
!
!
!
!
!
interface Null0
 no ip unreachables
!
interface GigabitEthernet0/0
 description $FW_INSIDE$
 ip address **.***.187.193 255.255.255.224
 no ip unreachables
 ip route-cache flow
 duplex full
 speed 100
 media-type rj45
 no cdp enable
!
interface GigabitEthernet0/1
 no ip address
 no ip unreachables
 ip route-cache flow
 shutdown
 duplex auto
 speed auto
 media-type rj45
!
interface Serial1/0
 description $FW_OUTSIDE$
 ip address ***.***.44.110 255.255.255.252
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 encapsulation ppp
 ip route-cache flow
 no ip mroute-cache
 dsu bandwidth 15790
 no cdp enable
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Serial1/0
!
ip flow-top-talkers
 top 10
 sort-by bytes
 cache-timeout 36000
!
ip http server
ip http authentication local
ip http secure-server
!
no cdp run
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 180 0
 password 7 **********************
 login
line aux 0
line vty 0 4
 exec-timeout 180 0
 password 7 **********************
 login
 transport input telnet
 transport output none
!
scheduler allocate 20000 1000
ntp update-calendar
!
end
0
Comment
Question by:ebs_it
  • 3
  • 3
6 Comments
 
LVL 2

Expert Comment

by:Reddustee
Comment Utility
not sure if i understand your setup correctly, but i shall try.
firstly, you may want to determine the line usage on the DS3 both in the incoming and outgoing directions.
inbound QoS is usually not effective because if the link was already congested, then the traffic would already have been dropped / delayed before reaching your router.
are the clients accessing server in your this location where the 3800 is and more traffic is download for them (i.e. upload from your site up to the DS3)? if yes, then maybe outbound/egress QoS will be more useful.
0
 

Author Comment

by:ebs_it
Comment Utility
yes clients are accessing an applicance/gateway at the same facility as the 3800 but behind a firewall.  Inbound/Outbound are pretty consistant with one another.

Could you provide the commands for egress QOS?  I'd like to set it up for the following ports 443, 2598, 1494.

 
0
 
LVL 2

Expert Comment

by:Reddustee
Comment Utility
If there isn't any congestion or high usage on the DS3 line, then QoS is not going to help.
By the way, the actual subscribed banwidth from Verizon is not DS3, is it? Because I noticed that you've put a "dsu bandwidth 15790" in your config.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:ebs_it
Comment Utility
The service is a DS3 provided by Verizon.  We've only commited to 15mb of bandwidth but it does allow for bursting up to the 45mb.  
0
 
LVL 2

Assisted Solution

by:Reddustee
Reddustee earned 20 total points
Comment Utility
Basic QoS configuration includes
- access-lists to identify the type of traffic you wish to categorise
- class-map to categorise your traffic
- policy-map to set the policy on each category of traffic (e.g. bandwidth)
- applying the policy-map to the interface (either in the egress or ingress direction)
 
Try referring to previous question on QOS or searching cisco/google for samples, e.g. http://www.experts-exchange.com/Hardware/Networking_Hardware/Routers/Q_22681478.html  
 
0
 

Accepted Solution

by:
ebs_it earned 0 total points
Comment Utility
There is a known compatibility issue with the Fujitisu SONET MUX and our Cisco 3800 series router.  This issue was idenitify by Verizon NOC.
 
To correct problem follow steps below:
Telnet into Router
config t
interface Serial1/0
scramble
wr mem
 
This command was also initialize on the opposite router node by a Verizon Engineer.  The Engineer also change the clock speed on his end from "line" to "internal".  The router on our end is set to "line".
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

New Server 172.16.200.2  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address 172.16.100.2. But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now