Solved

Internal websites outside firewall are slow

Posted on 2008-06-11
5
292 Views
Last Modified: 2010-04-21
For our security I'm going to be a little generic in this description. I just need to know what *might* be happening so I can look into it. Here's the deal...

We have a Cisco pix firewall and a 2900 XL switch outside of that firewall that connects a WAN to our location. A separate switch with multiple VLANS is also attached to the PIX. The issue is that access to web servers attached to the 2900 XL are painfully slow. If the web server is serving up only static HTML the speed is fine, but for the two web servers that hit a database to display content the speed is so bad it can 5 to 10 minutes to load the first and every page.

Here's the kicker. If these servers are accessed from outside system (ie, not coming from an internal VLAN) the speed is fine. What could be causing this issue?
0
Comment
Question by:Stormspace
  • 3
  • 2
5 Comments
 
LVL 7

Expert Comment

by:mabutterfield
Comment Utility
Have you checked speed / duplex on the interfaces of the Pix, and internal hosts?
0
 
LVL 1

Author Comment

by:Stormspace
Comment Utility
Ok, Checked the ports and everything is set to auto and full duplex.
0
 
LVL 7

Accepted Solution

by:
mabutterfield earned 125 total points
Comment Utility
have you checked the routing / NATing of connections between them?  

Also, have you tried other types of connections, such as ping, or file transfers to determine latency/throughput. (this may require loosening the rulebase temporarily.)

0
 
LVL 1

Author Comment

by:Stormspace
Comment Utility
Hmm. I'll have to look into that. It's something I haven't had to do yet.
0
 
LVL 1

Author Closing Comment

by:Stormspace
Comment Utility
We eventually had to replace the equipment. Part of the problem I feel was the Sys admin's use of a rogue bin file to reflash the PIX.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now