Solved

ASA5505 Poor Performance

Posted on 2011-03-22
6
1,068 Views
Last Modified: 2012-05-11
Hello there,

We have a Cisco ASA5505 configured at a clients site and it has been SLOW since configuring port forwarding after install.  Here is the configuration, see anything that could be causing this?  There is constantly 732kbps of outgoing WAN traffic that should not be there.

the 22.34.27.22 adress represents our single external IP  (changed for security purposes)
the 192.168.1.232 address is our internal mail/HTTPS server (needs ports 25,4125,443 forwarded)

: Saved
:
ASA Version 8.2(1) 
!
hostname CISCOASA
domain-name company.com
enable password f6YsckNYzxWEjFBV encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.1.1 255.255.255.0 
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 22.34.27.22 255.255.255.252 
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
ftp mode passive
dns server-group DefaultDNS
 domain-name company.com
object-group service DM_INLINE_TCP_0 tcp
 port-object eq https
 port-object eq imap4
 port-object eq pop3
 port-object eq pptp
 port-object eq smtp
object-group service rtp tcp
 port-object eq 4125
access-list outside_access_in extended permit tcp host 192.168.1.232 any object-group DM_INLINE_TCP_0 
access-list outside_access_in extended permit tcp any interface outside eq smtp 
access-list outside_access_in extended permit tcp any interface outside eq https 
access-list outside_access_in extended permit tcp any interface outside object-group rtp 
access-list outside_access_in2 extended permit tcp any interface outside eq pop3 
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) tcp interface smtp 192.168.1.232 smtp netmask 255.255.255.255 
static (inside,outside) tcp interface https 192.168.1.232 https netmask 255.255.255.255 
static (inside,outside) tcp interface 4125 192.168.1.232 4125 netmask 255.255.255.255 
access-group outside_access_in in interface outside
route outside 0.0.0.0 0.0.0.0 22.34.27.21 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
http server enable 444
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet 192.168.1.0 255.255.255.0 inside
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.1.5-192.168.1.36 inside
!

threat-detection basic-threat
threat-detection statistics
threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
webvpn
!
!
prompt hostname context 
Cryptochecksum:7e7d4d08582f9cc7cdd620eb41ffea82
: end

Open in new window

0
Comment
Question by:PCFix1011
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
6 Comments
 

Author Comment

by:PCFix1011
ID: 35195511
I've noticed that when looking at the traffic usage, there is about 700kbps unaccounted for......  That is, when you add up the "current bytes per second" usage between all protocols, there is a 700kbps discrepancy.  Very strange.
0
 

Author Comment

by:PCFix1011
ID: 35195593
It looks like it may be wild SMTP activity....
0
 
LVL 6

Expert Comment

by:kuoh
ID: 35195650
You should check that the mail server isn't an open relay and that there are no infected PCs on your network sending out spam.  You can start with an ACL that blocks all outbound SMTP traffic except those from the mail server.

KuoH
0
Are You Headed to Black Hat USA 2017?

Getting ready for Black Hat next week? Kick things off with the WatchGuard Badge Challenge and test your puzzle and cipher skills. Do you have what it takes to earn our limited edition Firebox Badge? Get started today - https://crimsonthorn.net

 

Author Comment

by:PCFix1011
ID: 35195855
When I disable the SMTP service on the server (SBS03) the traffic stops.  When enabled, it will be fine for a while, and then traffic will jump to the 700kbps range.  The strange thing is when I look at the "current sessions" and the mail queues, there is no activity.  I am beginning to wonder if there is a problem with the SMTP service on the server.
0
 

Accepted Solution

by:
PCFix1011 earned 0 total points
ID: 35196507
As it turns out, the SMTP Virtual Server and SMTP Connector were completely corrupted and malfunctioning.  I disabled the virtual server and created a new one, and deleted the SMTP connector, and re-created, and everything is working properly.

I figured out the corruption problem by using Wireshark to sniff the packets from the SBS03 server.  There were tons of fragmented packets with bad checksum going to various yahoo email servers.  Just about 700kbps of traffic....
0
 

Author Closing Comment

by:PCFix1011
ID: 35225550
CLUSTER FUCK
0

Featured Post

Are You Headed to Black Hat USA 2017?

Getting ready for Black Hat next week? Kick things off with the WatchGuard Badge Challenge and test your puzzle and cipher skills. Do you have what it takes to earn our limited edition Firebox Badge? Get started today - https://crimsonthorn.net

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

635 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question