<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If've already looked over the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954732#M155552</link>
    <description>&lt;P&gt;If've already looked over the limitations and there's only one thing that really bugs me. That is the 5 VLAN limit. To be honest, I can get a pretty good deal on the Sec Plus ASA so I think I'll just go for it...&lt;/P&gt;
&lt;P&gt;Well yes, the 150$ is a little bit understated.. I would need, just for example, the "L-ASA5506-TAM-1Y" right? This would cost me around 250$/year?&lt;/P&gt;
&lt;P&gt;Thanks for the link.. I'm not sure if I qualify since my employer is a Cisco reseller. Does the reseller part only include Meraki stuff or Cisco in general? If only Meraki is included I should qualify.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2016 08:16:08 GMT</pubDate>
    <dc:creator>ammann9113</dc:creator>
    <dc:date>2016-10-19T08:16:08Z</dc:date>
    <item>
      <title>ASA 5506-X performance experiences</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954728#M155548</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;I'm thinking about getting myself a 5506-X for home use. I know it might be overkill to some degree, expensive and so on... and to be honest, it really isn't necessary, but I like to play around and some educational purposes play a part to. So, this is not the kind of discussion I am interested in right now... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Just so you know, I am fairly experienced and I think of myself that I know what I am doing &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Anyway, enough with the unnecessary chit-chat... what holds me back right now is my current "unknowing" of what throughput the 5506-X is capable of. I know there is a data sheet with pretty numbers in it, but that's not what I am interested in. I want to know, what numbers I could really expect. Some "real-life" experiences...&lt;/P&gt;
&lt;P&gt;I am aware that this heavily depends on what features are activated... so what would the range be, coming from fort knox (everything on) to just waving at passerbys (everything off)? Although it's a little bit expensive (if I am understanding the licensing correctly) I would be playing around with that fancy FirePOWER stuff to some point.&lt;/P&gt;
&lt;P&gt;Another question I couldn't quite figure out myself is if the following scenario could be configured on the ASA; say we have a host X. Would it be possible to configure the ASA in a way that host X can load some files over port 80 without being bothered to much? Something like: traffic from host X over port 80 will not be inspected, hence more throughput for host X.&lt;/P&gt;
&lt;P&gt;Any input will be appreciated! And of course, I am not expecting too much, since my questions aren't straight yes/no questions.&lt;/P&gt;
&lt;P&gt;Be safe and have a nice evening &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954728#M155548</guid>
      <dc:creator>ammann9113</dc:creator>
      <dc:date>2019-03-12T08:24:57Z</dc:date>
    </item>
    <item>
      <title>I know it might be overkill</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954729#M155549</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;I know it might be overkill to some degree, expensive and so on... and to be honest, it really isn't necessary,&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;For sure it is! Every household should be protected by an ASA with FirePower or a Meraki MX! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For the ASA, you can control which traffic gets sent to the FirePOWER module. Traffic that is not sent&amp;nbsp;to FP&amp;nbsp;is "only" inspected by the ASA which gives you a peak performance of about 750 MBit/s.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For all traffic that is inspected with FirePOWER, expect a performance between 30 and 100 MBit/s, depending on which services you activate.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 16:05:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954729#M155549</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-10-18T16:05:14Z</dc:date>
    </item>
    <item>
      <title>Thanks, that's a great answer</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954730#M155550</link>
      <description>&lt;P&gt;Thanks, that's a great answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I'm planning on getting 500/50 MBit/s internet and it would kinda make me sad if my joy for the ASA would detain my speed-wise needs... and of course this needs are only for the occasional download so the probably 100 MBit/s will be fine for anything else.&lt;/P&gt;
&lt;P&gt;I have two follow-up questions, if you would be so kind (and able..):&lt;/P&gt;
&lt;P&gt;- If I get the ASA with security plus license, I still need to add a FirePOWER license right? And if I researched correctly, this would cost me about 150$ a year (for the "basic" FirePOWER lic)?&lt;/P&gt;
&lt;P&gt;- What's up with this whole Meraki stuff? To be honest, I didn't really hear/read about it until a few days ago... cloud managed, ok... well this only really comes into play if you have a lot of those right? Is it worth thinking about getting any same level Meraki device instead of the 5506-X?&lt;/P&gt;
&lt;P&gt;Thanks again and have a nice evening!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 18:07:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954730#M155550</guid>
      <dc:creator>ammann9113</dc:creator>
      <dc:date>2016-10-18T18:07:31Z</dc:date>
    </item>
    <item>
      <title>Differently to the old 5505,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954731#M155551</link>
      <description>&lt;P&gt;Differently to the old 5505, SecPlus is not often needed on the 5506-X as&amp;nbsp;the 5506-X doesn't have the same limitations:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/intro-license.html#concept_6FA65A78F1FF4CF4947EEF7AC74956C0"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/intro-license.html#concept_6FA65A78F1FF4CF4947EEF7AC74956C0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;FirePower is always licensed in addition to the base ASA. There are different license with different features like IPS, URL-Filtering and AMP.&amp;nbsp;What is this $150-license? I only know more expensive licenses ...&lt;/P&gt;
&lt;P&gt;Meraki? Well, It's a little bit like networking really should be. It's by far not as flexible as the regular Cisco-stuff, but I assume that it's the better solution for most companies. It's much easier to manage and there is also less possibility to configure it wrong. (Minimum 70% of all ASAs I see at customers have a really bad config and are not well&amp;nbsp;managed; that can all be done better with Meraki). Perhaps you qualify for a free AP when you attend a webinar: &lt;A href="https://meraki.cisco.com/de/freeap/"&gt;https://meraki.cisco.com/de/freeap/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 19:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954731#M155551</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-10-18T19:27:46Z</dc:date>
    </item>
    <item>
      <title>If've already looked over the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954732#M155552</link>
      <description>&lt;P&gt;If've already looked over the limitations and there's only one thing that really bugs me. That is the 5 VLAN limit. To be honest, I can get a pretty good deal on the Sec Plus ASA so I think I'll just go for it...&lt;/P&gt;
&lt;P&gt;Well yes, the 150$ is a little bit understated.. I would need, just for example, the "L-ASA5506-TAM-1Y" right? This would cost me around 250$/year?&lt;/P&gt;
&lt;P&gt;Thanks for the link.. I'm not sure if I qualify since my employer is a Cisco reseller. Does the reseller part only include Meraki stuff or Cisco in general? If only Meraki is included I should qualify.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 08:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954732#M155552</guid>
      <dc:creator>ammann9113</dc:creator>
      <dc:date>2016-10-19T08:16:08Z</dc:date>
    </item>
    <item>
      <title>hi karsten,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954733#M155553</link>
      <description>&lt;P&gt;hi karsten,&lt;/P&gt;
&lt;P&gt;i'm about to get my free meraki AP as well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;i've got a meraki ap/site deployment soon.&lt;/P&gt;
&lt;P&gt;but i'm choosing between that and the 'free trial' option.&lt;/P&gt;
&lt;P&gt;which one is better?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 08:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954733#M155553</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-10-19T08:26:35Z</dc:date>
    </item>
    <item>
      <title>I have exactly the same issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954734#M155554</link>
      <description>&lt;P&gt;I have exactly the same issue and are wondering about the performance.&lt;/P&gt;
&lt;P&gt;I have a 500/500Mbps glass fiber internet connection, connected through 1GbE; I get around 530/530Mbps on a speedtest. I want to buy an ASA 5506-X. I'm not planning to use the FirePOWER services. I wonder if it can handle 500/500Mbps throughput.&lt;/P&gt;
&lt;P&gt;Did you buy the 5506-X already? If so, what is your experience?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 22:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954734#M155554</guid>
      <dc:creator>Boudewijn Plomp</dc:creator>
      <dc:date>2016-10-21T22:15:21Z</dc:date>
    </item>
    <item>
      <title>Unfortunately, I did not.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954735#M155555</link>
      <description>&lt;P&gt;Unfortunately, I did not. Altough I am going to order the ASA in the next few days, I guess it will take a few weeks until I have it up and running.&lt;/P&gt;
&lt;P&gt;Anyway, I will post my findings here as soon as possible.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 07:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954735#M155555</guid>
      <dc:creator>ammann9113</dc:creator>
      <dc:date>2016-10-24T07:01:26Z</dc:date>
    </item>
    <item>
      <title>Rackmount Kit for Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954736#M155556</link>
      <description>&lt;P style="padding-left: 30px;"&gt;Rackmount Kit for Cisco ASA 5506 – CisRack RM-CI-T2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;US Distributed by Live-Tech&lt;/P&gt;
&lt;P&gt;https://www.mylive-tech.com/store/networking/networking-rackmount/rackmount-kit-for-cisco-asa-5506-cisrack-rm-ci-t2/&lt;/P&gt;</description>
      <pubDate>Sun, 30 Oct 2016 04:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954736#M155556</guid>
      <dc:creator>livetech2006</dc:creator>
      <dc:date>2016-10-30T04:55:31Z</dc:date>
    </item>
    <item>
      <title>quick update for anybody that</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954737#M155557</link>
      <description>&lt;P&gt;quick update for anybody that might be interested:&lt;/P&gt;
&lt;P&gt;i can get (probably as expected) my&amp;nbsp;full 500mbit down-speed through the ASA. currently there are just a few access rules, nothing heavy... unfortunately i do not have the equipment to test the peak throughput as i am currently just using one notebook and don't have anything else... anyway, i'll be doing this probably somewhen in the next 1-2 weeks.&lt;/P&gt;
&lt;P&gt;also the whole FirePOWER stuff... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; i'll post anything as soon as i get to it.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 19:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954737#M155557</guid>
      <dc:creator>ammann9113</dc:creator>
      <dc:date>2016-11-16T19:35:31Z</dc:date>
    </item>
    <item>
      <title>I have been putting 1gig</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954738#M155558</link>
      <description>&lt;P&gt;I have been putting 1gig through the 5506 without problems in a test setup. i tested with a filetransfer from one computer to another in different zones. But I have not stress tested it with max connection, because it is only used in a SOHO environment.&lt;/P&gt;
&lt;P&gt;With basic config: NAT, FW, Inspection&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2016 03:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954738#M155558</guid>
      <dc:creator>rasmus.elmholt</dc:creator>
      <dc:date>2016-11-19T03:59:14Z</dc:date>
    </item>
    <item>
      <title>Thanks for sharing. The only</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954739#M155559</link>
      <description>&lt;P&gt;Thank you for sharing. The only thing is; a file transer is not a valid test at all. If you re-try a file transfer it is cached and it looks like you get full speed, while in fact it doesn't.&lt;/P&gt;
&lt;P&gt;The best test is to use something like IPERF on the source and destination. Run a performance test with multiple sessions at the same time.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2016 09:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954739#M155559</guid>
      <dc:creator>Boudewijn Plomp</dc:creator>
      <dc:date>2016-11-19T09:50:43Z</dc:date>
    </item>
    <item>
      <title>I actually did the iperf test</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954740#M155560</link>
      <description>&lt;P&gt;I actually did the iperf test instead, and it showed me the 1gbit on 5 concurrent sessions i think. It was just easier to explain it as a file transfer here:)&lt;/P&gt;
&lt;P&gt;Again this is only a couple of connections so it cant be compare to real-world enterprise traffic, but it shows something about the performance in a SOHO environment.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Did the Remote-Access VPN test as well, and got 110-120 mbit through. So agoin performance above the baseline.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-733916.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;All the tests i did resulted in a CPU increase, because everything is done in SW, Routing, NAT, VPN, SSL offloading.&lt;/P&gt;
&lt;P&gt;40-60% for 1gbit TCP&lt;/P&gt;
&lt;P&gt;70-80% for 110 mbit VPN&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I tried the BlackNurse attack yesterday and did a test with 30mbit small UDP packets on random ports(both blocked and allowed) as well. It all resultet in defeat of the ASA during the test.&lt;/P&gt;
&lt;P&gt;99% for 20mbit BlackNurse/UDP traffic&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2016 11:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/2954740#M155560</guid>
      <dc:creator>rasmus.elmholt</dc:creator>
      <dc:date>2016-11-19T11:47:07Z</dc:date>
    </item>
    <item>
      <title>some more hints</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/3300637#M155561</link>
      <description>&lt;P&gt;I know this is sort of late, but let me share some $.02.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a few issues with internal systems being accessed from the outside world. Turns out TAC told me”because you have absolutely everything configured and active, well over 10k active IDS rules, and you are also doing SSL inspection, your max throughout will be limited to less than 3Mbps”.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So watch out for the Fort Knox type of config. Looks great on paper but it can definitively hog your device to death.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have balanced my rules to the point I have as much active and I can peak my 150Mbps up/down traffic with some spare change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enjoy your new toy &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 05:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-performance-experiences/m-p/3300637#M155561</guid>
      <dc:creator>HQuest</dc:creator>
      <dc:date>2017-12-22T05:26:31Z</dc:date>
    </item>
  </channel>
</rss>

