<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Maximum sessions ASA 5585-X CX SSP-10 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184488#M356929</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jouni.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Feb 2013 17:30:35 GMT</pubDate>
    <dc:creator>samuelsancho</dc:creator>
    <dc:date>2013-02-27T17:30:35Z</dc:date>
    <item>
      <title>Maximum sessions ASA 5585-X CX SSP-10</title>
      <link>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184483#M356924</link>
      <description>&lt;P&gt;Hi, I've a doubt about the maximum concurrent connections in ASA 5585-X with SSP10 CX module, from data sheet it seems that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-ASA 5585-X --&amp;gt; maximum concurrent connections 1.000.000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-ASA 5585-X CX SSP-10 with 8GE, DES --&amp;gt; maximum concurrent sessions 500.000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;BUT, what if I don't send all sessions to CX module??, could I use&amp;nbsp; more than 500.000 concurrent sessions in ASA 5585-X whenever SSP-10 module doesn't exceed 500.000??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184483#M356924</guid>
      <dc:creator>samuelsancho</dc:creator>
      <dc:date>2019-03-12T00:57:59Z</dc:date>
    </item>
    <item>
      <title>Maximum sessions ASA 5585-X CX SSP-10</title>
      <link>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184484#M356925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly I don't remember what was mentioned about this at Cisco Live! 2013 London. I seem to recal that they mentioned that this wouldnt be a problem but as I said I'm not 100% sure on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing related to this that I found on Cisco site with a fast look was this in the Q&amp;amp;A section.&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-style: normal; font-variant: normal; font-weight: normal; margin-left: 0pt; margin-right: 0pt; text-align: left; text-decoration: none; text-indent: 0pt; text-transform: none;"&gt;Performance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp9000076"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 0pt; margin-left: 18pt; margin-right: 0pt; margin-top: 0pt; text-decoration: none; text-indent: -18pt; text-transform: none;"&gt;&lt;SPAN style="font-family: Arial;"&gt;&lt;STRONG&gt;Q.&lt;/STRONG&gt;&lt;/SPAN&gt; How about performance? Will the CX blade slow down my ASA firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;
&lt;A name="wp9000077"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 7pt; margin-left: 18pt; margin-right: 0pt; margin-top: 0pt; text-decoration: none; text-indent: -18pt; text-transform: none;"&gt;&lt;SPAN style="font-family: Arial;"&gt;&lt;STRONG&gt;A.&lt;/STRONG&gt;&lt;/SPAN&gt; As with any device performing deep packet inspection, performance will&amp;nbsp; be lower than with devices that only route traffic or perform stateful&amp;nbsp; inspection. However, all ASA CX devices will provide gigabit and&amp;nbsp; multigigabit throughput levels. Unlike competitive offerings, which&amp;nbsp; require application control to be continuously active for all the&amp;nbsp; traffic, ASA CX does not create any such restriction. Administrators can&amp;nbsp; determine which traffic will be inspected by ASA CX, and continue to&amp;nbsp; use Layer 3/Layer 4 rules where deep packet inspection is not required.&amp;nbsp; This capability provides the flexibility for servers requiring&amp;nbsp; low-latency performance to be exempted from deep packet inspection and&amp;nbsp; still benefit from ASA stateful inspection. As a result, much more&amp;nbsp; efficient and higher-performance firewalling is possible, compared with&amp;nbsp; only creating application-based rules.&lt;/DIV&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will be having some people on a course related to this in the next week and I will be seing a Cisco employee about the ASA CX later this month.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 14:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184484#M356925</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-08T14:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum sessions ASA 5585-X CX SSP-10</title>
      <link>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184485#M356926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Jouni. Your anwser helps me and It will be very useful for me if you have more information regarding this question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2013 16:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184485#M356926</guid>
      <dc:creator>samuelsancho</dc:creator>
      <dc:date>2013-02-12T16:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum sessions ASA 5585-X CX SSP-10</title>
      <link>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184486#M356927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made a question last week to people from Cisco, and they confirm that whenever you don't exceed the 500.000 connections in ASA CX module you can have more than 500.000 connections in ASA module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not totally sure but this was the answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 17:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184486#M356927</guid>
      <dc:creator>samuelsancho</dc:creator>
      <dc:date>2013-02-27T17:20:05Z</dc:date>
    </item>
    <item>
      <title>Maximum sessions ASA 5585-X CX SSP-10</title>
      <link>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184487#M356928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry Samuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I forgot to answer this after the meeting with Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The answer I got was that if you have a configuration that forwards some certain networks traffic to the ASA CX and the ASA CX connection limit is reached THEN new connections simply wont be passed. There doesnt seem to be any mechanism that would automatically let traffic pass without going to CX if its connection limit is hit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was told that basicly to avoid these situations you would have to manually limit the traffic assigned to the ASA CX so that it wouldnt reach its concurrent connection limit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if this will be something that will be changed. To be honest I cant give any answers myself since I'm still waiting for the first ASA CX so I can start playing around with its configurations &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 17:25:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184487#M356928</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-27T17:25:27Z</dc:date>
    </item>
    <item>
      <title>Maximum sessions ASA 5585-X CX SSP-10</title>
      <link>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184488#M356929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jouni.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 17:30:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/maximum-sessions-asa-5585-x-cx-ssp-10/m-p/2184488#M356929</guid>
      <dc:creator>samuelsancho</dc:creator>
      <dc:date>2013-02-27T17:30:35Z</dc:date>
    </item>
  </channel>
</rss>

