<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FirePOWER add latency without any visible reason in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4292493#M1078514</link>
    <description>&lt;P&gt;After upgrade FP and except many traffic from it, we have no problem.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Feb 2021 15:51:17 GMT</pubDate>
    <dc:creator>Oleg Volkov</dc:creator>
    <dc:date>2021-02-16T15:51:17Z</dc:date>
    <item>
      <title>FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909627#M939475</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I have ASA with FirePOWER (no AMP and URL). And have many (over 10) zones.&lt;/P&gt;&lt;P&gt;yesterday my SIP server sometimes &amp;nbsp;loss registration and vice also have poor quality.&lt;/P&gt;&lt;P&gt;I try to PING 8.8.8.8 and get floating delay from 25 to 500! ms.&lt;/P&gt;&lt;P&gt;i exclude sip server traffic from FirePOWER module and get delay about 23-25 ms.&lt;/P&gt;&lt;P&gt;I change active ASA (also with FirePOWER) and first time after, delay was be normal, but not long time. How I can understand what traffic make FirePOWER unusable?&lt;/P&gt;&lt;P&gt;PS:&lt;/P&gt;&lt;P&gt;I do not have high traffic, but have many connection from outside to my WEB (https) server.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909627#M939475</guid>
      <dc:creator>Oleg Volkov</dc:creator>
      <dc:date>2020-02-21T17:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909775#M939476</link>
      <description>&lt;P&gt;What version are you running? There is a bug with 6.3 that can affect observed icmp latencies.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvo80715/?reffering_site=dumpcr" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvo80715&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 05:23:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909775#M939476</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-08-18T05:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909782#M939477</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;6.3 and now 6.3.13.&lt;/P&gt;&lt;P&gt;I have delay not only ICMP. SIP and DNS also delayed.&lt;/P&gt;&lt;P&gt;In bug reference I see workaround - disable hardware ssl acceleration but I do not use decryption.&lt;/P&gt;&lt;P&gt;What method of diagnostic you can recommended in case like this?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 07:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909782#M939477</guid>
      <dc:creator>Oleg Volkov</dc:creator>
      <dc:date>2019-08-18T07:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909803#M939478</link>
      <description>&lt;P&gt;They turned on "enable by default" behavior in 6.3. That has an unanticipated negative impact - even though you are not using the feature.&lt;/P&gt;
&lt;P&gt;The BugID only indicates icmp traffic is affected by the bug; but it may be that they didn't get any user reports of SIP and DNS traffic from users and thus haven't noted those are affected.&lt;/P&gt;
&lt;P&gt;You can do ahead and disable it from the cli (reboot required for it to take effect).&lt;/P&gt;
&lt;P&gt;And - yes - it is configured from the cli. It's one of the few features that is done that way with FTD.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 10:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909803#M939478</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-08-18T10:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909812#M939479</link>
      <description>&lt;P&gt;Sorry I provide wrong version:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ZES-ASA01/pri/act# sh module sfr&lt;/P&gt;&lt;P&gt;Mod Card Type Model Serial No.&lt;BR /&gt;---- -------------------------------------------- ------------------ -----------&lt;BR /&gt;sfr FirePOWER Services Software Module ASA5515 FCH18217YHB&lt;/P&gt;&lt;P&gt;Mod MAC Address Range Hw Version Fw Version Sw Version&lt;BR /&gt;---- --------------------------------- ------------ ------------ ---------------&lt;BR /&gt;sfr f40f.1b76.d347 to f40f.1b76.d347 N/A N/A 6.2.3.13-53&lt;/P&gt;&lt;P&gt;Mod SSM Application Name Status SSM Application Version&lt;BR /&gt;---- ------------------------------ ---------------- --------------------------&lt;BR /&gt;sfr ASA FirePOWER Up 6.2.3.13-53&lt;/P&gt;&lt;P&gt;Mod Status Data Plane Status Compatibility&lt;BR /&gt;---- ------------------ --------------------- -------------&lt;BR /&gt;sfr Up Up&lt;/P&gt;&lt;P&gt;And I think workaround is not applicable for me, sfr module not accepted commands:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class="highlight begin selected"&gt;system support &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="highlight middle selected"&gt;ssl&lt;/SPAN&gt;&lt;SPAN class="highlight middle selected"&gt;-&lt;/SPAN&gt;&lt;SPAN class="highlight middle selected"&gt;hw&lt;/SPAN&gt;&lt;SPAN class="highlight middle selected"&gt;-&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class="highlight end selected"&gt;offload disable&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;FTD&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;system support ssl&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;hw&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;force&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;offload&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;disable&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 12:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909812#M939479</guid>
      <dc:creator>Oleg Volkov</dc:creator>
      <dc:date>2019-08-18T12:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909814#M939480</link>
      <description>&lt;P&gt;Ah correct - sorry that command is for FTD only. You did say you are using ASA with Firepower service module.&lt;/P&gt;
&lt;P&gt;Are you inspecting icmp, sip and dns in your ASA config? What is the ASA version (not Firepower version)?&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 12:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909814#M939480</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-08-18T12:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909816#M939481</link>
      <description>&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.6(4)3&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect icmp&lt;BR /&gt;inspect pptp&lt;BR /&gt;inspect icmp error&lt;BR /&gt;class IPS-CM&lt;BR /&gt;sfr fail-open&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 12:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3909816#M939481</guid>
      <dc:creator>Oleg Volkov</dc:creator>
      <dc:date>2019-08-18T12:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3910043#M939482</link>
      <description>&lt;P&gt;Everything appears in order with your config.&lt;/P&gt;
&lt;P&gt;I'd suggest opening a TAC case for a more detailed look in real time.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 08:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/3910043#M939482</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-08-19T08:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4006265#M939483</link>
      <description>&lt;P&gt;Did we have a resolution to this? Oleg were you able to resolve this with TAC?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 21:40:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4006265#M939483</guid>
      <dc:creator>irshad.hirani</dc:creator>
      <dc:date>2020-01-03T21:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4006272#M939484</link>
      <description>No, we except part of traffic from FP and now latency is acceptable.</description>
      <pubDate>Fri, 03 Jan 2020 21:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4006272#M939484</guid>
      <dc:creator>Oleg Volkov</dc:creator>
      <dc:date>2020-01-03T21:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4292322#M1078507</link>
      <description>&lt;P&gt;We have the same Problem with 6.6.1-91 and ASA 5555x any new ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 11:35:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4292322#M1078507</guid>
      <dc:creator>BURKHARD LANDWEHR</dc:creator>
      <dc:date>2021-02-16T11:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: FirePOWER add latency without any visible reason</title>
      <link>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4292493#M1078514</link>
      <description>&lt;P&gt;After upgrade FP and except many traffic from it, we have no problem.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 15:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-add-latency-without-any-visible-reason/m-p/4292493#M1078514</guid>
      <dc:creator>Oleg Volkov</dc:creator>
      <dc:date>2021-02-16T15:51:17Z</dc:date>
    </item>
  </channel>
</rss>

