Link to home
Create AccountLog in
Avatar of Cashbuddies
Cashbuddies

asked on

Bandwidth limited by ASA

I have a 20Mbit/sec leased line with no limit on burst download. When I test download speeds, I can see that it is limited to 25Mbit/sec. I moved them onto our old PIX to test it, and the bandwidth seems to reach 50Mbit/sec with it. This is a huge difference.
All other equipment is equal when I run the tests. Same server, same switch port. The only change is the gateway is switched from the ASA to the pix. What would cause this? The interface port on both is set to 100Mb/full, as is the next device that they connect to in the data centre.
CPU on the ASA stays around 8-9% during my tests.
I do have IPS enabled on the ASA, could this be the cause?
SOLUTION
Avatar of BurundiLapp
BurundiLapp
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Avatar of Cashbuddies
Cashbuddies

ASKER

Hi,
I can't remove the ASA and connect directly, as the next hop is not in our control.
I have control over the other end point, and everything is the same. A slight difference could be explained as a slight variation from the endpoint, but this is twice the bandwidth. Huge difference.

For more info:
Memory is around 11%.
And I notice that the outside interface on the asa has 66884 input errors, and they are all overrun errors.
Avatar of Pete Long
>>the asa has 66884 input errors, and they are all overrun errors.

Set the speed and duplex of this interface manually
SOLUTION
Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
Yep, its already set to 100full.
I cleared the stats for the input errors, and haven't had any more since. These were probably old ones from when we did change from auto to 100full back a few years ago.
Is the traffic passed through the IPS module you have in the ASA? Depending on the configuration of the IPS, this can have serious impact on the throughput. Each packet passing through the IPS will be inspected, which costs time, slowing down traffic.
I do have IPS enabled on the ASA, could this be the cause?

According to this thread (https://supportforums.cisco.com/thread/2081067) there is a bug (CSCsv69844).

Workaround is to set the Regex Depth Setting to 800000.

Instructions here:  http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsv69844
I have logged a TAC with cisco.
I'll see what they recommend. Thanks for the pointers so far
Which ASA model do you have?  Some obviouly are more powerful than others.

How many interface are connected and what are all their speeds?

The through-put a ASA  (even a PIX) can handle is total through-put between all interfaces combined.
It's a 5510 with 4 x 100Mb interfaces in use, a failover interface, and 2 VLANS.
ASKER CERTIFIED SOLUTION
Link to home
membership
Create an account to see this answer
Signing up is free. No credit card required.
Create Account
We have AIP SSM-10.
When I tested it I only moved this one server over to the PIX.

That could well explain the discrepancy. I have PRTG monitor on all the interfaces, so I can look at the  usage on the other interfaces whenever I see low throughput on the outside interface.
I'll close this off as I think that's a fair explanation. This morning the speed reached 65Mbit/sec with the ASA.
Thanks for the points.

Using PRTG (or any other SNMP type tool) will help.  However, you only want to total up the bps on the inbound side of each interface.  That will give you the total amount of traffic that is flowing through the ASA.  Ignore the outbound bps.