Slow PBR for Interface
-
I have a Site-to-Site IPSec setup and all my test show that the link is stable and responsive. It's only a 25/5 link, so no where near worrying about IPSec bottlenecks, but what I have noticed is that when I use PBR to steer traffic down the VTI, there's some serious lag in the routing, whereas if I just static route to the VTI, then I don't have the lag.
I'm curious if the packet forwarding is seriously "gimped" when going through the PBR process? If so, is it as simple as upgrading to a system that has more horsepower? I don't see CPU usage high at all, but the graphs are not second by second so there could be some stuff falling through the statistics gap.
My purpose for the PBR is to use a gateway group that, based on latency and packet loss, has the VTI as Tier1 and the local WAN as Tier2. If folks can think of a better way of doing this, I'm all ears. My eventual hope is the PBR will only be used for RTSP based services, but for now just having all traffic for a given VLAN interface use the PBR is fine.