<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Questionable FTD Egress Latency in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/questionable-ftd-egress-latency/m-p/4644928#M1091638</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;So to confirm, hops 7 and 8 are directly connected using ethernet cable&lt;BR /&gt;(i.e no L2 network between them or ISP is not hiding IPs).? This is&lt;BR /&gt;important to confirm cuz you might be having another network in between or&lt;BR /&gt;a microware link for example which can add latency.&lt;BR /&gt;&lt;BR /&gt;Next, if FTD CPU is high, it can cause slowness and its important to know&lt;BR /&gt;why a single CPU is at high usage continuously (you might be having an&lt;BR /&gt;elephant flow which is constantly inspected by FTD such as backup).&lt;BR /&gt;&lt;BR /&gt;Here is a good resource for troubleshooting.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-3121.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-3121.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
    <pubDate>Wed, 06 Jul 2022 11:18:45 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2022-07-06T11:18:45Z</dc:date>
    <item>
      <title>Questionable FTD Egress Latency</title>
      <link>https://community.cisco.com/t5/network-security/questionable-ftd-egress-latency/m-p/4644664#M1091622</link>
      <description>&lt;P&gt;Multiple users have recently reported connection slowness to an APP VM that they have access to through an FTD HA Pair in our Colo DC. After running a trace from their access switch to the server that sites behind the firewall, I noticed that while going through the egress interface of the FTD alone is around 75ms on average. We do not do any heavy L7 packet inspection, just L3/L4 Security Rules, so I am a bit confused about the reason for the high latency. Is this latency time normal to see on an FTD? Is there any possible way to work to bring this time down? Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1 172.30.254.70 2 msec&lt;BR /&gt;172.30.254.68 2 msec&lt;BR /&gt;172.30.254.70 2 msec&lt;BR /&gt;2 172.30.254.0 2 msec&lt;BR /&gt;172.30.254.2 3 msec&lt;BR /&gt;172.30.254.0 1 msec&lt;BR /&gt;3 172.30.211.253 2 msec 3 msec 1 msec&lt;BR /&gt;4 172.30.77.10 1 msec 2 msec 1 msec&lt;BR /&gt;5 10.62.250.153 4 msec 4 msec 4 msec&lt;BR /&gt;6 10.251.5.106 [MPLS: Label 24369 Exp 0] 5 msec 5 msec 5 msec&lt;BR /&gt;7 10.251.15.113 4 msec 4 msec 4 msec&lt;BR /&gt;&lt;STRONG&gt;8 10.93.16.1 76 msec 75 msec 78 msec&amp;nbsp; &amp;nbsp; FTD EGRESS INTERFACE (NEXT HOP SERVER)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;UPDATE:&amp;nbsp;&lt;/STRONG&gt;I have noticed that within FMC, the CPU0 is currently sitting around 85-90%. Could this be a legit reason for the high latency? If so, could a possible reboot solve this? Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 23:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questionable-ftd-egress-latency/m-p/4644664#M1091622</guid>
      <dc:creator>CarsonDavis56998</dc:creator>
      <dc:date>2022-07-05T23:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: Questionable FTD Egress Latency</title>
      <link>https://community.cisco.com/t5/network-security/questionable-ftd-egress-latency/m-p/4644870#M1091635</link>
      <description>&lt;P&gt;even though you not using the L7 inspection on FTD but by default if no rules are configured the default policy kicks in. what you can do is create a L7 ACP rule and put the server and user in "Trust". by doing this FTD will not do a default policy check.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/212321-clarify-the-firepower-threat-defense-acc.html" target="_self"&gt;Here&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="trust.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/155247i0B524617A4735070/image-size/large?v=v2&amp;amp;px=999" role="button" title="trust.PNG" alt="trust.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 09:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questionable-ftd-egress-latency/m-p/4644870#M1091635</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-07-06T09:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Questionable FTD Egress Latency</title>
      <link>https://community.cisco.com/t5/network-security/questionable-ftd-egress-latency/m-p/4644928#M1091638</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;So to confirm, hops 7 and 8 are directly connected using ethernet cable&lt;BR /&gt;(i.e no L2 network between them or ISP is not hiding IPs).? This is&lt;BR /&gt;important to confirm cuz you might be having another network in between or&lt;BR /&gt;a microware link for example which can add latency.&lt;BR /&gt;&lt;BR /&gt;Next, if FTD CPU is high, it can cause slowness and its important to know&lt;BR /&gt;why a single CPU is at high usage continuously (you might be having an&lt;BR /&gt;elephant flow which is constantly inspected by FTD such as backup).&lt;BR /&gt;&lt;BR /&gt;Here is a good resource for troubleshooting.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-3121.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-3121.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 06 Jul 2022 11:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questionable-ftd-egress-latency/m-p/4644928#M1091638</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-07-06T11:18:45Z</dc:date>
    </item>
  </channel>
</rss>

