Connection per sec limit reached in ASA 5550, need ideas for temporary relief
Posted on 2015-01-16
I have a Cisco ASA 5550 that is seeing performance issues due to the sheer number of packets per sec. Per Cisco documentation it can support 35k conn/sec. From this command, I understand this is the average connections per sec, which is well over.
CiscoASA550# sho conn count
58395 in use, 73811 most used
This is causing input errors on the inside interface, over and under runs.
One idea I have to lower the amount of connections is to lower the "timeout conn" value to drop idle connections quicker.
How low can I safely go? This firewall is mostly used to NAT a connection to load balancers, for web browsing.
Next idea, but I'm not sure if I'm right. If I change the default ASA MSS from 1380 to:
sysopt connection tcpmss 1460
sysopt connection tcpmss minimum 0
Would that help? I don't know if it would lower connections, I think it would just help throughput.
Any ideas to safely lower connection counts until hardware is upgraded, is appreciated.