Solved

ASP page slow in initial connection

Posted on 2008-06-13
5
1,073 Views
Last Modified: 2013-11-16
Hi Experts,
I have a nasty question here which drives me crazy for the last week and I don't seem to get a answer from the net.
We just upgraded our datacenter, with a two new Firewalls, both a Juniper SSG-320m which run in HA.
I put some webservers and sqlserver in there and now the problem starts.
A regular unix machine with apache and PHP is fast as lightning, but in the same acces rule (port 80 untrust to front-end zone) a Windows 2003 IIS server hosting a heavy .aspx page takes literaly 21 seconds to load.
I see in my logs a session is created but the request to the server has a timeout of 20 seconds.
So even when I have stopped the application it takes 20 seconds to get the server error.
Yesterday I put the server directly on the net, and then the performance is fine, but now back behing the SSG's the error is there again. I had a play with the ALGS and virus detection, but it didn;t seem to work. Maybe it has something to do with the Adress translation.
Is anyone familiar with this problem or can tell me what to to, because I'm quite desperate.

500 for the winning answer.
0
Comment
Question by:RedAdvanced
  • 3
  • 2
5 Comments
 
LVL 32

Expert Comment

by:dpk_wal
ID: 21784780
Frankly I am not sure what is causing the problem; but I think if you have turned ALG they might be causing the problem; can you check if you disable ALG then what is the behavior.
ALG does packet inspection and hence would introduce latency; latency is even introduced by the firewall itself; NAT, packet inspection and other things like antivirus would also cause latency.

As I said earlier I am not 100% sure, but would be interesting to see the results.

Thank you.
0
 
LVL 1

Author Comment

by:RedAdvanced
ID: 21801296
That's what I thought of aswell, but after turning off ALG for all known services the performance wasn't getting better.

I also turned of all packet filters, anti-virus etc. just to see it would make any diffrence, but no. Nothing seemed to have caused the latency.
0
 
LVL 1

Author Comment

by:RedAdvanced
ID: 21801301
What also needs to be mentioned, is that this firewall cluster is brand new. There are hardly other servers behind it that a DNS server and a apache webserver, which are actually running fine.
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 21803720
I am sorry but I am not sure what else might be causing such a behavior; if linux works good so should windows; may be some other expert might have some suggestion.

Regards.
0
 
LVL 1

Accepted Solution

by:
RedAdvanced earned 0 total points
ID: 21844742
I have found the solution, and it was actually provided by a support tech @ Juniper (thanks Manish)

We had to set the "all-tcp-mss" option
The default explenation of this option is:

Sets the TCP-MSS (TCP-Maximum Segment Size) value for all TCP packets for
network traffic. This also sets the TCP-MSS for IPSec VPN traffic if the tcp-mss
option (described below) is not set. If you enter the set flow tcp-mss
command, that setting overrides the all-tcp-mss option for VPN traffic.
The TCP-MSS range can be from 0 to 65,535 bytes. By default, the
all-tcp-mss option is unset.

By setting the maximum segment size to 1320 the problem was gone.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sonicwall multiple ISP configuration 5 59
How do I modify Ubigate for new ISP? 2 96
Resource cost of NAT vs routing 3 75
How to safely test out TFTP server software 12 68
Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question