<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA slow internet connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892831#M177240</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Im facing problems with my internet connection, we have 100Mb/s but when we do some tests we just have 50mb/s, the ISP aready made some tests before the firewall and the speed is 100mb/s, so the my asa can be the problem.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Someone has an idea about this?.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:27:15 GMT</pubDate>
    <dc:creator>dotansplus</dc:creator>
    <dc:date>2019-03-12T07:27:15Z</dc:date>
    <item>
      <title>ASA slow internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892831#M177240</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Im facing problems with my internet connection, we have 100Mb/s but when we do some tests we just have 50mb/s, the ISP aready made some tests before the firewall and the speed is 100mb/s, so the my asa can be the problem.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Someone has an idea about this?.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:27:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892831#M177240</guid>
      <dc:creator>dotansplus</dc:creator>
      <dc:date>2019-03-12T07:27:15Z</dc:date>
    </item>
    <item>
      <title>Hi dotansplus,</title>
      <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892832#M177241</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://supportforums.cisco.com/users/dotansplus" title="View user profile." class="username" lang="" about="/users/dotansplus" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;&lt;G class="gr_ gr_10 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="10" data-gr-id="10"&gt;dotansplus&lt;/G&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;Can you please share the output of&amp;nbsp;&lt;BR /&gt;show run all &lt;G class="gr_ gr_11 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="11" data-gr-id="11"&gt;sysopt&lt;/G&gt;&lt;BR /&gt;show run all | in df-bit&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Check this link:&lt;BR /&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/82444-fragmentation.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/82444-fragmentation.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Under "&lt;G class="gr_ gr_129 gr-alert gr_gramm undefined Punctuation multiReplace" id="129" data-gr-id="129"&gt;Troubleshoot :&lt;/G&gt; VPN Encryption Error" segment, check the steps to test the fragmentation and tweak the MSS accordingly on the ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 16:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892832#M177241</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-03-08T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892833#M177242</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you check the speed/duplex settings on the ASA's outside interface ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_115 gr-alert gr_gramm undefined Punctuation multiReplace" id="115" data-gr-id="115"&gt;Also&lt;/G&gt; share the output of show interface | in error on the ASA ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 16:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892833#M177242</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-08T16:04:24Z</dc:date>
    </item>
    <item>
      <title>Hi Dinesh,</title>
      <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892834#M177243</link>
      <description>&lt;P&gt;Hi Dinesh,&lt;/P&gt;
&lt;P&gt;I´m not quite sure if that the problem, I´m not using a VPN with my provider or maybe the slowness is caused by my VPNs?&lt;/P&gt;
&lt;P&gt;here is the information:&lt;/P&gt;
&lt;P&gt;#show run all sysopt&lt;BR /&gt;no sysopt connection timewait&lt;BR /&gt;sysopt connection tcpmss 1300&lt;BR /&gt;sysopt connection tcpmss minimum 0&lt;BR /&gt;no sysopt connection permit-vpn&lt;BR /&gt;sysopt connection reclassify-vpn&lt;BR /&gt;no sysopt connection preserve-vpn-flows&lt;BR /&gt;no sysopt radius ignore-secret&lt;BR /&gt;no sysopt noproxyarp lan&lt;BR /&gt;no sysopt noproxyarp wiredclientb&lt;BR /&gt;no sysopt noproxyarp wiredclienta&lt;BR /&gt;no sysopt noproxyarp voice1&lt;BR /&gt;no sysopt noproxyarp voice2&lt;BR /&gt;no sysopt noproxyarp mobile&lt;BR /&gt;no sysopt noproxyarp restri1&lt;BR /&gt;no sysopt noproxyarp restri2&lt;BR /&gt;no sysopt noproxyarp route&lt;BR /&gt;no sysopt noproxyarp wan&lt;BR /&gt;no sysopt noproxyarp outside&lt;BR /&gt;no sysopt noproxyarp man&lt;BR /&gt;no sysopt noproxyarp dmz-s&lt;BR /&gt;no sysopt noproxyarp dmz-w&lt;BR /&gt;no sysopt noproxyarp dmz-wm&lt;BR /&gt;no sysopt noproxyarp dmz-mg&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;# show run all | i df-bit&lt;BR /&gt;crypto ipsec df-bit copy-df lan&lt;BR /&gt;crypto ipsec df-bit copy-df wiredclientb&lt;BR /&gt;crypto ipsec df-bit copy-df wiredclienta&lt;BR /&gt;crypto ipsec df-bit copy-df voice1&lt;BR /&gt;crypto ipsec df-bit copy-df voice2&lt;BR /&gt;crypto ipsec df-bit copy-df mobile&lt;BR /&gt;crypto ipsec df-bit copy-df restri1&lt;BR /&gt;crypto ipsec df-bit copy-df restri2&lt;BR /&gt;crypto ipsec df-bit copy-df route&lt;BR /&gt;crypto ipsec df-bit copy-df wan&lt;BR /&gt;crypto ipsec df-bit copy-df outside&lt;BR /&gt;crypto ipsec df-bit copy-df man&lt;BR /&gt;crypto ipsec df-bit copy-df dmz-s&lt;BR /&gt;crypto ipsec df-bit copy-df dmz-w&lt;BR /&gt;crypto ipsec df-bit copy-df dmz-wm&lt;BR /&gt;crypto ipsec df-bit copy-df dmz-mg&lt;BR /&gt; anyconnect ssl df-bit-ignore disable&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let me know what you think&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 09:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892834#M177243</guid>
      <dc:creator>dotansplus</dc:creator>
      <dc:date>2016-03-09T09:15:58Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892835#M177244</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;For the outside interface I use a vlan&lt;/P&gt;
&lt;P&gt;This is the physical interface gi0/0:&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt; description outside&lt;BR /&gt; speed 1000&lt;BR /&gt; duplex full&lt;BR /&gt; no nameif&lt;BR /&gt; security-level 0&lt;BR /&gt; no ip address&lt;/P&gt;
&lt;P&gt;Interface GigabitEthernet0/0 "", is up, line protocol is up&lt;BR /&gt; Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; Full-Duplex(Full-duplex), 1000 Mbps(1000 Mbps)&lt;/P&gt;
&lt;P&gt;IP address unassigned&lt;BR /&gt; 554019012 packets input, 542908648178 bytes, 0 no buffer&lt;BR /&gt; Received 364784 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 8467 input errors, 0 CRC, 0 frame, 8467 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 223861 L2 decode drops&lt;BR /&gt; 414235553 packets output, 174547878158 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 4 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The vlan that I use for the outside interface:&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/0.x&lt;BR /&gt; description outside&lt;BR /&gt; vlan x&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address x.x.x.x z.z.z.z&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface GigabitEthernet0/0.x "outside", is up, line protocol is up&lt;BR /&gt; Hardware is yyyyyy rev03, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt; VLAN identifier x&lt;BR /&gt; Description: outside&lt;BR /&gt; MAC address f.f.f.f, MTU 1500&lt;BR /&gt; IP address x.x.x.x, subnet mask x.x.x.x&lt;BR /&gt; Traffic Statistics for "outside":&lt;BR /&gt; 553175373 packets input, 529833230269 bytes&lt;BR /&gt; 413731846 packets output, 164842026809 bytes&lt;BR /&gt; 3534044 packets dropped&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show interface | in error&lt;BR /&gt;8467 input errors, 0 CRC, 0 frame, 8467 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 output errors, 0 collisions, 4 interface resets&lt;BR /&gt; 174190 input errors, 0 CRC, 0 frame, 174190 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 output errors, 0 collisions, 3 interface resets&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 output errors, 0 collisions, 2 interface resets&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What do you think?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 09:16:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892835#M177244</guid>
      <dc:creator>dotansplus</dc:creator>
      <dc:date>2016-03-09T09:16:32Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892836#M177245</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see a lot of overruns on the interfaces.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show interface | in error&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8467 input errors, 0 CRC, 0 frame, &lt;STRONG&gt;8467 overrun&lt;/STRONG&gt;, 0 ignored, 0 abort&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;0 output errors, 0 collisions, 4 interface resets&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;174190 input errors, 0 CRC, 0 frame, &lt;STRONG&gt;174190 overrun,&lt;/STRONG&gt; 0 ignored, 0 abort&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;0 output errors, 0 collisions, 3 interface resets&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;What is the CPU usage of the &lt;G class="gr_ gr_167 gr-alert gr_gramm undefined Punctuation multiReplace" id="167" data-gr-id="167"&gt;ASA ?&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any recent changes in the &lt;G class="gr_ gr_214 gr-alert gr_gramm undefined Punctuation multiReplace" id="214" data-gr-id="214"&gt;network ?&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What is the traffic rate like, do we see bursty traffic ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Interface &lt;/SPAN&gt;&lt;STRONG&gt;overruns, no buffer&lt;/STRONG&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;STRONG&gt;underruns&lt;/STRONG&gt;&lt;SPAN&gt; often show that the firewall cannot process all the traffic it is receiving on its NIC. Overruns and no buffers indicate that input traffic is too much on a given interface. The interface maintains a receive ring where packets are stored before they are processed by the ASA. If the NIC is receiving traffic faster than the ASA can pull them off the receive ring, the packet will be dropped and either the no buffer or overrun counter will increment. Underruns behaviour similarly but deal with the transmit ring instead.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can check this link:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;https://supportforums.cisco.com/document/47506/asa-oversubscription-interface-errors-troubleshooting&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also&amp;nbsp;would you please do a clear interface, clear traffic, wait 5 minutes and then do a show traffic, show Interface?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please rate helpful posts.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 18:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892836#M177245</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-09T18:34:37Z</dc:date>
    </item>
    <item>
      <title>Hello Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892837#M177246</link>
      <description>&lt;P&gt;Hello Aditya,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for the reply, this is the cpu usage right now:&lt;/P&gt;
&lt;P&gt;CPU utilization for 5 seconds = 23%; 1 minute: 17%; 5 minutes: 16%&lt;/P&gt;
&lt;P&gt;I saw the graphs since 1 year ago and the max was 45%&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There was not any change with the network, the traffic is normal, not any bursty traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In the graphics I see that the last year, since we have 100mb/s we were just using 20Mb/s, our provicer already make some test and before the firewall the link speed is 100mb/s&lt;/P&gt;
&lt;P&gt;sad&lt;/P&gt;
&lt;P&gt;Also, I have the ASA 5520 and the&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;max throughput&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;is&amp;nbsp;450 Mbps, what am I missing?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 12:41:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/2892837#M177246</guid>
      <dc:creator>dotansplus</dc:creator>
      <dc:date>2016-03-10T12:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: Hello Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/4145723#M1073552</link>
      <description>&lt;P&gt;Hello! I encountering the same issue. please help..&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 11:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-slow-internet-connection/m-p/4145723#M1073552</guid>
      <dc:creator>Benj31</dc:creator>
      <dc:date>2020-09-03T11:41:53Z</dc:date>
    </item>
  </channel>
</rss>

