<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WSA HTTPS interception slow upload in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879848#M6581</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_58 gr-alert gr_gramm gr_run_anim Punctuation multiReplace" id="58" data-gr-id="58"&gt;Currently&lt;/G&gt; I'm doing a WSA project at a customer with HTTPS interception. I've noticed when doing uploads over HTTPS (&lt;G class="gr_ gr_135 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="135" data-gr-id="135"&gt;fe&lt;/G&gt;&amp;nbsp;google drive or &lt;G class="gr_ gr_153 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="153" data-gr-id="153"&gt;wetransfer&lt;/G&gt;), the performance is very poor. Uploading a file over intercepted HTTPS goes at a rate of about 1,5Mbps. When I do the same upload (same file and same online service) without &lt;G class="gr_ gr_452 gr-alert gr_gramm gr_run_anim Grammar only-ins doubleReplace replaceWithoutSep" id="452" data-gr-id="452"&gt;interception&lt;/G&gt;, it goes at about 50Mbps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTTP uploads and intercepted HTTPS downloads also go at normal speeds. The performance hit is present on both S380 appliances and they are currently only being used for testing (no load). I also tried disabling CDS and outbound malware scanning without results.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Has anybody seen&amp;nbsp;this difference in BW for uploads over intercepted HTTPS? Should I consider it as normal?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kr&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jun 2016 08:53:46 GMT</pubDate>
    <dc:creator>askaerr</dc:creator>
    <dc:date>2016-06-21T08:53:46Z</dc:date>
    <item>
      <title>WSA HTTPS interception slow upload</title>
      <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879848#M6581</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_58 gr-alert gr_gramm gr_run_anim Punctuation multiReplace" id="58" data-gr-id="58"&gt;Currently&lt;/G&gt; I'm doing a WSA project at a customer with HTTPS interception. I've noticed when doing uploads over HTTPS (&lt;G class="gr_ gr_135 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="135" data-gr-id="135"&gt;fe&lt;/G&gt;&amp;nbsp;google drive or &lt;G class="gr_ gr_153 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="153" data-gr-id="153"&gt;wetransfer&lt;/G&gt;), the performance is very poor. Uploading a file over intercepted HTTPS goes at a rate of about 1,5Mbps. When I do the same upload (same file and same online service) without &lt;G class="gr_ gr_452 gr-alert gr_gramm gr_run_anim Grammar only-ins doubleReplace replaceWithoutSep" id="452" data-gr-id="452"&gt;interception&lt;/G&gt;, it goes at about 50Mbps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTTP uploads and intercepted HTTPS downloads also go at normal speeds. The performance hit is present on both S380 appliances and they are currently only being used for testing (no load). I also tried disabling CDS and outbound malware scanning without results.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Has anybody seen&amp;nbsp;this difference in BW for uploads over intercepted HTTPS? Should I consider it as normal?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kr&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 08:53:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879848#M6581</guid>
      <dc:creator>askaerr</dc:creator>
      <dc:date>2016-06-21T08:53:46Z</dc:date>
    </item>
    <item>
      <title>We haven't heard the same</title>
      <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879849#M6582</link>
      <description>&lt;P&gt;We haven't heard the same from other customer yet. Can you please run packet capture at WSA without any filter for HTTPs decryption enable and disable one and then compare them to see if you can find any clue?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 01:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879849#M6582</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-06-23T01:11:53Z</dc:date>
    </item>
    <item>
      <title>How do you authenticate users</title>
      <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879850#M6583</link>
      <description>&lt;P&gt;How do you authenticate users? and which AsyncOS version are you using? I have experienced something similar to what you see.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;All HTTPS traffic was slow in our case, and this was due to authentication issues.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 06:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879850#M6583</guid>
      <dc:creator>RoadRunner4k</dc:creator>
      <dc:date>2016-06-29T06:33:24Z</dc:date>
    </item>
    <item>
      <title>We're doing explicit proxy</title>
      <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879851#M6584</link>
      <description>&lt;P&gt;We're doing explicit proxy and the WSA appliances are on 9.0.1-162. Disabling authentication for a specific IP address as a test did not show any improvements.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In fact it seems we're only experiencing these issues with Google Drive. No difference is noticed (in comparison with the old non-intercepting proxy) when using wetransfer or dropbox.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've tried comparing packet captures when doing interception and when not but can't seem to find any hints in there.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 08:19:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879851#M6584</guid>
      <dc:creator>askaerr</dc:creator>
      <dc:date>2016-06-29T08:19:16Z</dc:date>
    </item>
    <item>
      <title>Thanks for your update. As I</title>
      <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879852#M6585</link>
      <description>&lt;P&gt;Thanks for your update. As I could not reproduce this issue, would you please try the following steps to narrow down this issue.&lt;/P&gt;
&lt;P&gt;1. Disable "&lt;SPAN class="s1"&gt;Decrypt for Application Detection" in HTTPs proxy settings if it is enabled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;2. Try deploying another version virtual WSA to test it again to see if it is only happening on this specific version.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please feel free to open a new Cisco TAC case and we do provide 24x7x365 support.&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 23:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879852#M6585</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2016-06-29T23:50:25Z</dc:date>
    </item>
    <item>
      <title>Thanks for your suggestions.</title>
      <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879853#M6586</link>
      <description>&lt;P&gt;Thanks for your suggestions.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1. The "Decrypt for Application Detection" feature was disabled but no results, the upload speeds remain very slow.&lt;/P&gt;
&lt;P&gt;2. I did not find the time yet to test with a virtual WSA on a different version but will try to do so next week.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In the &lt;G class="gr_ gr_222 gr-alert gr_gramm gr_run_anim Punctuation only-ins replaceWithoutSep" id="222" data-gr-id="222"&gt;meanwhile&lt;/G&gt; I logged a case at the Cisco PDI helpdesk (Cisco TAC did not want to take the case because it's a new setup) but no progress yet.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 12:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879853#M6586</guid>
      <dc:creator>askaerr</dc:creator>
      <dc:date>2016-07-06T12:27:53Z</dc:date>
    </item>
    <item>
      <title>See the following the thread.</title>
      <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879854#M6587</link>
      <description>&lt;P&gt;See the following the thread.&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/12485001/wsa-slowing-upload-speed-half&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 17:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879854#M6587</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2016-07-19T17:23:44Z</dc:date>
    </item>
    <item>
      <title>Thanks for the tip.</title>
      <link>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879855#M6588</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the tip.&lt;/P&gt;
&lt;P&gt;I tried to disable the Data Security Policy but no change in behavior. Also upgraded to 9.1.1-074 but no difference. PDI closed the case and &lt;G class="gr_ gr_285 gr-alert gr_tiny gr_gramm gr_run_anim Grammar multiReplace" id="285" data-gr-id="285"&gt;I&lt;/G&gt;"m not working with TAC to check what we can do.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 12:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-https-interception-slow-upload/m-p/2879855#M6588</guid>
      <dc:creator>askaerr</dc:creator>
      <dc:date>2016-09-05T12:36:46Z</dc:date>
    </item>
  </channel>
</rss>

