<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS/SSL upload speed is slow through FTD with SSL Policy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4194962#M1076495</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Speed test uses port TCP/8080 for download and upload. So no direct&lt;BR /&gt;relation between SSL policy and speed test. However, SSL policy drops the&lt;BR /&gt;performance of any hardware including firepower as it needs to perform&lt;BR /&gt;decryption and encryption for every packet (if you use resign).&lt;BR /&gt;&lt;BR /&gt;In your case, cert check won't cause decryption/encryption cause this is&lt;BR /&gt;inspected in SSL handshake.&lt;BR /&gt;&lt;BR /&gt;Try to do a pcap to see the destination server for speed test. Then apply a&lt;BR /&gt;test pre-filter policy to fastpath that traffic and see if it improves.&lt;BR /&gt;This is to isolate if FTD is doing something to speed tes traffic specific&lt;BR /&gt;or its general ssl inspection for all traffic.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
    <pubDate>Tue, 08 Dec 2020 06:50:02 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2020-12-08T06:50:02Z</dc:date>
    <item>
      <title>HTTPS/SSL upload speed is slow through FTD with SSL Policy</title>
      <link>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4194883#M1076493</link>
      <description>&lt;P&gt;I have FTD1K running 6.6.1 (build 91) managed by FMC...&lt;/P&gt;&lt;P&gt;From a user laptop inside network to run speedtest via speedtest.net in browser, I got about 150Mbps down and 1Mbps up...What I found is disabling the SSL policy on FTD improved dramatically on upload speed (increase to about 80Mbps)... but the SSL Policy configured is a fairly basic cert checking policy like screenshots below (defaults are used in other tabs of the policy/rule). But why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/90028i5967020BF4918032/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/90029i57D0AEC446AB2C08/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 01:34:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4194883#M1076493</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2020-12-08T01:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS/SSL upload speed is slow through FTD with SSL Policy</title>
      <link>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4194962#M1076495</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Speed test uses port TCP/8080 for download and upload. So no direct&lt;BR /&gt;relation between SSL policy and speed test. However, SSL policy drops the&lt;BR /&gt;performance of any hardware including firepower as it needs to perform&lt;BR /&gt;decryption and encryption for every packet (if you use resign).&lt;BR /&gt;&lt;BR /&gt;In your case, cert check won't cause decryption/encryption cause this is&lt;BR /&gt;inspected in SSL handshake.&lt;BR /&gt;&lt;BR /&gt;Try to do a pcap to see the destination server for speed test. Then apply a&lt;BR /&gt;test pre-filter policy to fastpath that traffic and see if it improves.&lt;BR /&gt;This is to isolate if FTD is doing something to speed tes traffic specific&lt;BR /&gt;or its general ssl inspection for all traffic.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 08 Dec 2020 06:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4194962#M1076495</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-12-08T06:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS/SSL upload speed is slow through FTD with SSL Policy</title>
      <link>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4195147#M1076506</link>
      <description>&lt;P&gt;With the policy I have in place, it should not consume much of the FTD performance. Even it did, why only "throttle" the upload, not the download direction?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also speedtest.net was just an example, I also tried onedrive and google cloud for uploading with similar slowness.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 13:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4195147#M1076506</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2020-12-08T13:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS/SSL upload speed is slow through FTD with SSL Policy</title>
      <link>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4280936#M1077725</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;I have same problem&amp;nbsp; ,&amp;nbsp; What was done and solved. Is there any improvement ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 21:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4280936#M1077725</guid>
      <dc:creator>aliozturk9@gmail.com</dc:creator>
      <dc:date>2021-01-27T21:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS/SSL upload speed is slow through FTD with SSL Policy</title>
      <link>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4281278#M1077748</link>
      <description>&lt;P&gt;If you use the FTD 1K platform, reach out to TAC and they would provide you a hot fix for the issue on v6.6.1.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 11:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-ssl-upload-speed-is-slow-through-ftd-with-ssl-policy/m-p/4281278#M1077748</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2021-01-28T11:24:42Z</dc:date>
    </item>
  </channel>
</rss>

