Link to home
Create AccountLog in
Routers

Routers

--

Questions

--

Followers

Top Experts

Avatar of jkeegan123
jkeegan123🇺🇸

Cisco ASA 5505 - Slow VPN Tunnels
I have a L2L tunnel between (2) Cisco ASA 5505's.  They are running ios v8.25 and the VPN attributes are:

3DES-MD5-HMAC, Group2, Lifetime 86400, tcp-mss default of 1380

Both systems speedtest out correctly.

Everything negotiates fine and I get a Main Mode tunnel that never drops or has issues...

I have a 50 MB Syncronous connection on one side and a 10MB Syncronous connection on the other side.  When I do speed testing with IPERF in server mode on one side, client mode on another, I get disappointing results and I'm not sure if I'm just measuring in the wrong units (Mbit vs mbit, Meg/s vs M/s) or if this is VASTLY underperforming.  Here's what I do, and here's what I get:

On the client side, I connect IPERF using port 20000 with command:
iperf -c [server.ip.goes.here] -L 20000 -d -f m

On the server side, I run default:
iperf -s

my results are:
On Client:

Client connecting to [server IP], TCP port 5001
TCP window size: 0.06 MByte (default)
------------------------------------------------------------
[404] local [client.ip] port 60701 connected with [server IP] port 5001
[420] local [client.ip] port 20000 connected with [server IP] port 5906
[ ID] Interval       Transfer     Bandwidth
[404]  0.0-10.1 sec  5.66 MBytes  4.70 Mbits/sec
[420]  0.0- 9.9 sec  28.9 Mbits  2.91 Mbits/sec

On Server:

Client connecting to [Client.IP], TCP port 20000
TCP window size: 64.0 KByte (default)
------------------------------------------------------------
[  5] local [server IP] port 59065 connected with [Client.IP] port 20000
[  4]  0.0-10.0 sec  5.66 MBytes  4.75 Mbits/sec
[  5]  0.0-10.0 sec  4.00 GBytes  3.43 Gbits/sec

Am I getting what you'd expect when the remote end is a 10MB internet connection?  Or is this bad throughput?  I had hoped for more.  I tried dropping 3DES to single DES and the results were almost identical (ever so slightly better, not a huge difference at all).

Thoughts ?

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


SOLUTION
Avatar of Blue Street TechBlue Street Tech🇺🇸

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

Avatar of Henk van AchterbergHenk van Achterberg🇳🇱

And also update to the latest version. This can also cause performance increase!

ASKER CERTIFIED SOLUTION
Avatar of asavenerasavener🇺🇸

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.

Avatar of jkeegan123jkeegan123🇺🇸

ASKER

It is at 1380,I adjusted it upwards and it got worse, downwards did not have much effect. I also changed the vpn df bit setting with no results (from copy to delete, I'm operating from memory), and it's currently still at the changed setting, and that was without negative or positive Effect.

By the way, I am testing throughput with iperf with one setting as client and one running as server, and the results are consistently between 3 and 5M.

Avatar of asavenerasavener🇺🇸

You only see the poor results at a certain time of day?

Is this a production network, with other network traffic on the ASAs?

If so, it sounds like network congestion.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Avatar of jkeegan123jkeegan123🇺🇸

ASKER

No all the time, even off hours.

Avatar of asavenerasavener🇺🇸

You might also try performing multiple simultaneous transfers.

Also, have you performed speed tests at both sites to verify you're getting the promised bandwidth?

Avatar of jkeegan123jkeegan123🇺🇸

ASKER

Bandwidth confirmed with speed test. Net

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


SOLUTION
Avatar of jkeegan123jkeegan123🇺🇸

ASKER

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.

Avatar of jkeegan123jkeegan123🇺🇸

ASKER

summary in my post is valid
Routers

Routers

--

Questions

--

Followers

Top Experts

A router is a networking device that forwards data packets between computer networks. Routers perform the "traffic directing" functions on the Internet. The most familiar type of routers are home and small office cable or DSL routers that simply pass data, such as web pages, email, IM, and videos between computers and the Internet. More sophisticated routers, such as enterprise routers, connect large business or ISP networks up to the powerful core routers that forward data at high speed along the optical fiber lines of the Internet backbone. Though routers are typically dedicated hardware devices, use of software-based routers has grown increasingly common.