Wednesday, May 15, 2019

policing / shaping recommendations

So i've got a 200 meg ip-vpn connection from CLINK. I've applied a shaper policy to the interface that states 'shape average percent 100', and on the interface, i've set bandwidth 200000.

I've got a serious problem with traffic leaving the site. Some hosts can send >60 Mb/sec just fine (windows server 2k8r2), others (windows server 2012 and windows server 2k8r2) can't send over 2 megabit/sec. Traffic bursts at 8mb/sec, then 2.1, then 0 and the connection drops. wireshark shows 'fast retransmissions' and 'duplicate ack', leading me to believe that packets are delivered out of order. Testing with iperf3 over TCP. 4 VM's talk fine, 2 are crap. 1 happens to be my veeam server, which really sucks, because it can't even push the runtime to my storage nodes to run jobs.

Now, traffic the other direction (into the site / vms), runs at full speed, no problem. Even on those two 'problem' vm's that cant talk out the site without all the packet loss and disconnects.

The problem machines can also talk to other servers onsite at full speed, no problems. Only when traffic hits the wan and leaves the site is there a problem. Doesn't matter if it's heading to any of the other three sites, same issue. Which leads me to believe that the problem is this one site and it's connection.

router is cisco isr c1111p running 16.9.3. CLINK says they are getting > 200 megabit/second, and are hard dropping packets over that rate. Even if that's so, why are some hosts sending data fine, and others a complete failure?

I see no errors on any interfaces. all speeds and duplex's are good.

Also, if I fall back to my existing 60 meg circuit, everything is fine.

It's got me stumped.

iperf3 -- VM -- B200m3 -- 2208FEX -- FI -10G- C2960s -1G- 4507r -2x1g- isr1111 -1g- clink NID -//- clink NID -1g- c1111 -2x1g- 6509VSS -2x10g- C220M3 -- iperf3



No comments:

Post a Comment