<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Slow SSH FTP (SFTP) transfer issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858506#M459068</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just want to make sure we're talking about the same thing.&amp;nbsp; SFTP uses ssh transport mechanism.&amp;nbsp; It uses tcp port 22.&lt;/P&gt;&lt;P&gt;FTPs is completely something else.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using SFTP (similar to SCP) which uses tcp port 22 or something else?&amp;nbsp; If you're using SFTP try to transfer again using scp and see if it makes any differences.&amp;nbsp; The firewall does not know anything about this connection because it is an "encrypted" connection between y our laptop and the server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Feb 2012 21:03:21 GMT</pubDate>
    <dc:creator>david.tran</dc:creator>
    <dc:date>2012-02-20T21:03:21Z</dc:date>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858505#M459066</link>
      <description>&lt;P&gt;We are having an issue with SFTP slow transfers, here is the network setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laptop --&amp;gt; ASA --&amp;gt; CSS --&amp;gt; Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laptop = Inside Interface&lt;/P&gt;&lt;P&gt;Server = Security Level 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default gateway for the servers is the CSS.&amp;nbsp; When we try just FTP it is very fast.&amp;nbsp; When I put laptop on the same network as the servers SFTP is fast.&amp;nbsp; But when I plug&amp;nbsp; my laptop the way I explained above SFTP is very very slow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did another test:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laptop --&amp;gt; CSS --&amp;gt; Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now in this scenario where the servers are no longer behind the firewall SFTP is also fast.&amp;nbsp; Doesn't make sense why when there is a firewall in the picture it is so slow because its not FTP and it shouldn't require any inspect statements or any other configuration.&amp;nbsp; Any ideas will be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858505#M459066</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2019-03-11T22:32:52Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858506#M459068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just want to make sure we're talking about the same thing.&amp;nbsp; SFTP uses ssh transport mechanism.&amp;nbsp; It uses tcp port 22.&lt;/P&gt;&lt;P&gt;FTPs is completely something else.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using SFTP (similar to SCP) which uses tcp port 22 or something else?&amp;nbsp; If you're using SFTP try to transfer again using scp and see if it makes any differences.&amp;nbsp; The firewall does not know anything about this connection because it is an "encrypted" connection between y our laptop and the server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2012 21:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858506#M459068</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-02-20T21:03:21Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858507#M459070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct I'm doing SFTP that uses SSH Port 22 not doing FTPS either. Using SCP doesn't make any difference either.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried multiple clients too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2012 21:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858507#M459070</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2012-02-20T21:12:59Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858508#M459072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok.&amp;nbsp; Mine setup is a the same as&amp;nbsp; yours with the following exception:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I have a pair of Pix firewalls instead of ASA running version 8.0(4),&lt;/P&gt;&lt;P&gt;- Instead of CSS, I have F5 BigIP as the Load-balancer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both FTP and SFTP going across the the firewall without any issues.&amp;nbsp; On the 100M interface, I am getting about 95mbps with both FTP and SFTP.&amp;nbsp; Ofcourse, with SFTP, my server takes some CPU hits because of SSH encryption.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2012 22:06:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858508#M459072</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-02-20T22:06:30Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858509#M459074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hum yeah that is pretty much we have other than F5's.&amp;nbsp; Well also client is on a different network than the server and the default gateway for the servers is the CSS.&amp;nbsp; Client come in through the inside interface of the firewall and servers are behind a NATed interface.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the interface IP is 10.1.1.1 and servers are behind that interface as 10.1.2.xx.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2012 22:32:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858509#M459074</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2012-02-20T22:32:48Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858510#M459076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you running any rate-limiting or QoS on the ASA?&amp;nbsp; what is the output of "show service-policy"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2012 22:47:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858510#M459076</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-02-20T22:47:24Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858511#M459078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Global policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns preset_dns_map, packet 36305306, drop 3956, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 203668, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225 _default_h323_map, packet 327, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras _default_h323_map, packet 1, drop 1, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 461, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rtsp, packet 331, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: esmtp _default_esmtp_map, packet 193239, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 3651, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny , packet 328, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 294629, drop 678, reset-drop 1039&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 1348&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 4363, drop 3720, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip , packet 696, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp-proxy: bytes in buffer 0, bytes dropped 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 164768, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 1759067, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ip-options _default_ip_options_map, packet 0, drop 0, reset-drop&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 16:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858511#M459078</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2012-02-21T16:05:58Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858512#M459079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohammand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am the engineer working on the case you have, the configuration looks good, the interfaces does not have any errors, the inspection policies are great. so but the next thing to troubleshoot to determine if this is te ASA indeed will be to conenct a PC to one ASA's interface ( directly connected) and then try to use the SFTP.&lt;/P&gt;&lt;P&gt;We could also do captures on the ASA on both interfaces inside and outside to determine what is going on!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 17:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858512#M459079</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-21T17:28:14Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858513#M459080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How are you connecting the laptop to the CSS?&amp;nbsp; Is it on the same network as the back end servers or is it on the front side network in front of the CSS?&amp;nbsp; Is the traffic destined to a VIP or is it destined to a back end server behind the CSS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does 'show perfmon' and 'show resource usage' show on the ASA during the transfer through the firewall?&amp;nbsp; Are you sure you're links aren't saturated?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 02:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858513#M459080</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2012-02-22T02:33:03Z</dc:date>
    </item>
    <item>
      <title>Slow SSH FTP (SFTP) transfer issue</title>
      <link>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858514#M459081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have tried to connect it to the same switch where the back end servers are connected and it works fine.&amp;nbsp; We also by passed the firewall and it works fine.&amp;nbsp; Its only when CSS is in between and we try to do the transfer to the Physical IP of the server it is slow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 13:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-ssh-ftp-sftp-transfer-issue/m-p/1858514#M459081</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2012-03-13T13:38:18Z</dc:date>
    </item>
  </channel>
</rss>

