Solved

Single external website extremely slow on internal network (via internet)

Posted on 2010-11-15
3
1,542 Views
Last Modified: 2012-08-13
We are having an issue with a specific website that some of our users access for business purposes.

The website has become very slow and unresponsive since the past two weeks. We have Websense integrated with our ASA 5520 appliance for internet filtering.

This is the only website we are experiencing issues with. Symptoms include webpage timeouts, slow browsing between pages, very slow downloads ( a 1Mb PDF will take 5-10 minutes to download). Our internet connection is not the issue as every other website is fast.

I noticed through various troubleshooting this problem only occurs on our network. When I hit the website from an alternate network (home, DMZ,) it responds quickly. As soon as we try from our internal network, it is slow like molasses.

We tried turning off Websense web filtering, network agent, put an except rule in the firewall to allow all traffic to the website IP range through, as well as the source client IP.

We also looked at our ASA configuration lines pertaining to the websense filtering.

The following config is present:

url-block block 32
url-mempool 10240
protocol tcp version 4 connections 60

These parameters were implemented a while back to solve other issues we were having.

One odd thing I noticed is when pinging the website from our internal network, I am receiving 10-15% packet loss. From an external network, hardly any packet loss. Again this is specific to this one website, everything else is fine.

Any ideas?

The website in question is www.orbit.com
0
Comment
Question by:pharmascience
3 Comments
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 250 total points
ID: 34142185
You need to find out what is dropping the packets.  If you are getting a 10-15% packet loss that will cause serious performance problems.

I would do a packet capture from the ASA.
0
 
LVL 28

Accepted Solution

by:
bgoering earned 250 total points
ID: 34145572
This is likely a mss issue - take a look at http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml for details as how to determine if this is your problem and how to implement a workaround.

Good Luck
0
 

Author Comment

by:pharmascience
ID: 34175580
Thanks guys
0

Featured Post

Save the day with this special offer from ATEN!

Save 30% on the CV211 using promo code EXPERTS30 now through April 30th. The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Telepresence on backup 3 54
replacing 2811 to ISR 4331 2 38
Setting up a trunk port on a Cisco switch? 20 57
sharing subnet on sonicwall 10 22
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question