<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Throughput issues in Cisco ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/throughput-issues-in-cisco-asa-5510/m-p/2246231#M350866</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like only the http traffic that is not giving the throughput, the VPN and all other traffic is perfectly working. Also as i mentioned earlier if we use a Download Accelerator then i can easily download with 10 Mbps speed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea is this behavior due to any inspection ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the below configuration, any idea will this impact the internet browsing and download rate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map netflow-export-class&lt;/P&gt;&lt;P&gt; match access-list netflow-export&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map http-port&lt;/P&gt;&lt;P&gt; match port tcp eq www&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt; class netflow-export-class&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; flow-export event-type all destination 10.10.10.21&lt;/P&gt;&lt;P&gt;policy-map type inspect http inbound_http&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt; match request body length gt 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match response body length gt 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match not request body length gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match not response body length gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match req-resp content-type mismatch&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match request header content-type violation&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match response header content-type violation&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match request header length gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match request uri length gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; class _default_gator&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt; class _default_kazaa&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt; class _default_msn-messenger&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt; class _default_aim-messenger&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt; class _default_yahoo-messenger&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt;policy-map inbound_policy&lt;/P&gt;&lt;P&gt; class http-port&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http inbound_http&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;call-home reporting anonymous&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Apr 2013 12:26:25 GMT</pubDate>
    <dc:creator>VAbr AVib</dc:creator>
    <dc:date>2013-04-29T12:26:25Z</dc:date>
    <item>
      <title>Throughput issues in Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/throughput-issues-in-cisco-asa-5510/m-p/2246230#M350864</link>
      <description>&lt;P&gt;For internet connectivity, we have a Cisco Firewall connected to a BGP router multihomed with 2 ISP. Attached the high level diagram for reference. &lt;/P&gt;&lt;P&gt;We have noticed that the bandwidth usage over the primary connectivity is less than 5 % of the total 100 mbps internet bandwidth, same way if i route the traffic via the secondary path then the bandwidth goes at an average up to 30 %.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have noticed that if i use any fast download softwares like DAP, then i am getting a speed of almost 10 Mbps but the normal usage is not crossing 5%. Is there any settings in ASA that i have to do to make this primary interface use more bandwidth. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/throughput-issues-in-cisco-asa-5510/m-p/2246230#M350864</guid>
      <dc:creator>VAbr AVib</dc:creator>
      <dc:date>2019-03-12T01:36:14Z</dc:date>
    </item>
    <item>
      <title>Throughput issues in Cisco ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/throughput-issues-in-cisco-asa-5510/m-p/2246231#M350866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like only the http traffic that is not giving the throughput, the VPN and all other traffic is perfectly working. Also as i mentioned earlier if we use a Download Accelerator then i can easily download with 10 Mbps speed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea is this behavior due to any inspection ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the below configuration, any idea will this impact the internet browsing and download rate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map netflow-export-class&lt;/P&gt;&lt;P&gt; match access-list netflow-export&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map http-port&lt;/P&gt;&lt;P&gt; match port tcp eq www&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt; class netflow-export-class&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; flow-export event-type all destination 10.10.10.21&lt;/P&gt;&lt;P&gt;policy-map type inspect http inbound_http&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt; match request body length gt 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match response body length gt 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match not request body length gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match not response body length gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match req-resp content-type mismatch&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match request header content-type violation&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match response header content-type violation&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match request header length gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; match request uri length gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset log&lt;/P&gt;&lt;P&gt; class _default_gator&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt; class _default_kazaa&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt; class _default_msn-messenger&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt; class _default_aim-messenger&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt; class _default_yahoo-messenger&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt;policy-map inbound_policy&lt;/P&gt;&lt;P&gt; class http-port&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http inbound_http&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;call-home reporting anonymous&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 12:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/throughput-issues-in-cisco-asa-5510/m-p/2246231#M350866</guid>
      <dc:creator>VAbr AVib</dc:creator>
      <dc:date>2013-04-29T12:26:25Z</dc:date>
    </item>
  </channel>
</rss>

