Solved

Cisco ASA 5510 Slow Throughput

Posted on 2011-03-02
7
7,455 Views
Last Modified: 2012-05-11
I have a Cisco ASA 5510 that I'm having throughput problems with.  I can't seem to get more than about 13MBps throughput from the inside <-> outside or inside <-> dmz (I have not tried dmz <-> outside.)  All interfaces are hard coded to speed 100 / duplex full; the devices on either side of the firewall are Cisco devices (a 3550 that is our Internet router) with a hard coded 100 / full applied to the interface facing the firewall, and on the inside I have a 3560 with a hard coded 100 / full applied to the interface facing the firewall.  Neither the 3550 or the 3560 are showing errors on the interfaces facing the firewall.  In short - I don't think this is a speed/duplex issue.

I have replaced the wiring to no avail.  I am running the latest switch IOS on both the 3560 and the 3550, and 8.2(4) on the ASA.  All devices have been rebooted (and we've had this issue for a while, but now that I have a 75MBps circuit to the 3550, I'd like to get more than 13MBps through the firewall.)  The speed is being tested with speedtest.net as well as a speed testing system provided by the ISP; if I plug a laptop into another port on the 3550 and configure it correctly, I get a speed rating of about 70MBps.

The firewall is on a VLAN that has only it and the interface on the 3560 switch.  I believe this is a variation of the recommended method of connecting the firewall to the network (rather than having it on a network with other devices.)

Let me be clear - it works - it's just very slow in comparison to what I expect.

0
Comment
Question by:gnurph
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
7 Comments
 
LVL 9

Expert Comment

by:gavving
ID: 35023377
Lets try this test.

Login into the ASDM and watch the bandwidth usage graph.

Find a place where you can download a very large file.  Windows AIK is a good choice.  it's 1.7GB.
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=696dd665-9f76-4177-a811-39c26d3b3b34&displaylang=en

Start that download.

Now do the same thing on 5 other computers, or as many as you can.

What does the bandwidth usage graph show?  Due to alot of things, your not likely to see transfers at 75mbit just because you have 75mbit.  Now if you start alot of file transfers running at the same time, you're more likely to see alot of bandwidth usage....

0
 

Author Comment

by:gnurph
ID: 35023395
The speed test was conducted via http://www.speedtest.net and http://speedtest.alliedtelecom.net - as I noted, both gave about the same results inside the firewall and outside the firewall -

about 13Mbps inside
about 70Mbps outside

Having multiple machines doing downloads won't impact that - their sum total will be about 13Mbps.  If I can get 70Mbps outside with a single machine, I certainly should get something close to that inside with a single machine.
0
 
LVL 24

Assisted Solution

by:rfc1180
rfc1180 earned 250 total points
ID: 35023456
> Neither the 3550 or the 3560 are showing errors on the interfaces facing the firewall.  In short - I don't think this is a speed/duplex issue.

What about on the ASA interfaces?

> if I plug a laptop into another port on the 3550 and configure it correctly, I get a speed rating of about 70MBps

That is a good test, eliminates the ISP and the 3550 (possibly, maybe a hardware issue on the port, maybe something related to the ASIC, buffers, etc).

what happens when you connect a laptop directly to the interface on the ASA, same thing?
0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 
LVL 9

Assisted Solution

by:gavving
gavving earned 250 total points
ID: 35023463
I missed that bit of information in the original post, sorry about that.  

I can get 75mbit on our 5510s through our Internet connection, so I know it can do it.  Ours is configured in much the same way.  Going through layer-3 3560s with the ASA on it's own vlan.  I know you mentioned that you checked the ports for errors on the switches connected to the ASA, but did you check the ASA interfaces for errors?  Does the 'show int' output show errors?  Also what is your CPU usage that you normally see on the ASA?  When you do the speed test is the CPU usage effected?  You can monitor that with ASDM as well, or 'show cpu usage'.
0
 

Accepted Solution

by:
gnurph earned 0 total points
ID: 35023548
Problem solved.  For reference, this ASA was also serving as a Cisco phone proxy; the telephony vendor had placed a 9Mbps policy limit on bandwidth to try and ensure that the telephone connections didn't get dropped due to high bandwidth utilization - the ASA was originally on a 10Mbps circuit.

Thanks, guys - I'll split the points on general principles.
0
 

Author Comment

by:gnurph
ID: 35023550
Problem solved.  For reference, this ASA was also serving as a Cisco phone proxy; the telephony vendor had placed a 9Mbps policy limit on bandwidth to try and ensure that the telephone connections didn't get dropped due to high bandwidth utilization - the ASA was originally on a 10Mbps circuit.

Thanks, guys - I'll split the points on general principles.
0
 

Author Closing Comment

by:gnurph
ID: 35067791
Problem solved by beating my head against the wall after I remembered what the phone vendor did.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction This article explores the design of a cache system that can improve the performance of a web site or web application.  The assumption is that the web site has many more “read” operations than “write” operations (this is commonly the ca…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question