<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic security levels and performance in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761173#M1008655</link>
    <description>&lt;P&gt;On a pix 515e ver. 7.0, I've set security levels between the inside and the dmz to 100. Is there anything else I should consider to allow unrestricted access between these two interfaces, I'm experiencing traffic delays from inside to dmz but not from dmz to inside.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:54:07 GMT</pubDate>
    <dc:creator>boondocker</dc:creator>
    <dc:date>2019-03-11T09:54:07Z</dc:date>
    <item>
      <title>security levels and performance</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761173#M1008655</link>
      <description>&lt;P&gt;On a pix 515e ver. 7.0, I've set security levels between the inside and the dmz to 100. Is there anything else I should consider to allow unrestricted access between these two interfaces, I'm experiencing traffic delays from inside to dmz but not from dmz to inside.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761173#M1008655</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2019-03-11T09:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: security levels and performance</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761174#M1008665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Didn't you post the same question yesterday in the thread titled, "Slow traffic from inside to DMZ"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After fixing your speed/duplex issues if the problem persists you need to use the capture feature on the PIX to capture the packets so we can see what is causing the slowdown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, you don't need to set the interfaces to the same security level - unless you just want to).  Since you most likely upgraded from 6.x to 7.x, if you are not using statics, or nat 0, then you need to disable nat-control by issuing the command "no nat-control".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 13:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761174#M1008665</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-03-30T13:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: security levels and performance</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761175#M1008674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David,&lt;/P&gt;&lt;P&gt;I did publish the packet capture but got no response (figured the results were a non-issue). I'm not using NAT between the inside and dmz although I am using NAT between the outside and the dmz.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 14:08:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761175#M1008674</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-30T14:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: security levels and performance</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761176#M1008679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Boondocker,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just checked again on the other thread, and I don't see the captures.  Can you attach them to this thread?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: I am assuming you know how to capture the packets on the PIX.  Please make sure you create two seperate captures, one on the DMZ interface, and one on the Inside - using an ACL to limit the traffic to be captured to just the two IPs doing the transfer. Then do your test,  then upload the two capture files in pcap format so we can have a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need help with capture, please let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 14:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761176#M1008679</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-03-30T14:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: security levels and performance</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761177#M1008686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you could help me out with the commands it would get me started. thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 15:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761177#M1008686</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-30T15:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: security levels and performance</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761178#M1008691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;- Assuming interfaces named inside and dmz&lt;/P&gt;&lt;P&gt;- Assuming IP of host on DMZ is 10.1.1.2&lt;/P&gt;&lt;P&gt;- Assuming IP of host on inside is 192.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Given the above, if you are not translating the inside host when it goes to the dmz, then you only need one ACL to match the traffic you want to capture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  access-list cap permit ip host 10.1.1.2 host 192.1.1.2&lt;/P&gt;&lt;P&gt;  access-list cap permit ip host 192.1.1.2 host 10.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has two entries to capture both directions of traffic.  Next, you create the captures - one on each interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  capture dmz int dmz access-list cap packet-l 1500&lt;/P&gt;&lt;P&gt;  capture in int inside access-list cap packet-l 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once applied, initiate the transfer.  The default buffer on the captures is 512 bytes (this can be changed using the 'buffer' option).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To pull the captures off the pix, you can use the copy command to do it via TFTP, or you can use HTTPS to pull them off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  copy /pcap capture:dmz t&lt;A class="jive-link-custom" href="ftp://" target="_blank"&gt;ftp://&lt;/A&gt;&lt;IP&gt;/&lt;FILENAME&gt;&lt;/FILENAME&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then reapeat for the inside capture as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, you can use https to pull them off:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   &lt;A class="jive-link-custom" href="https://" target="_blank"&gt;https://&lt;/A&gt;&lt;IP_OF_PIX&gt;/capture/dmz/pcap&lt;/IP_OF_PIX&gt;&lt;/P&gt;&lt;P&gt;   &lt;A class="jive-link-custom" href="https://" target="_blank"&gt;https://&lt;/A&gt;&lt;IP_OF_PIX&gt;/capture/in/pcap&lt;/IP_OF_PIX&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;once pulled off, just upload - or you can look at them yourself in ethereal/wireshark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 15:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761178#M1008691</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2007-03-30T15:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: security levels and performance</title>
      <link>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761179#M1008695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all the suggestions, I set my DMZ switch to a different VLAN then the inside and it fixed the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2007 13:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-levels-and-performance/m-p/761179#M1008695</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-04-18T13:42:38Z</dc:date>
    </item>
  </channel>
</rss>

