<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zone based firewall slowing downloads in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818439#M459936</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I had exactly the same experience on an SR520 (basically an 877 with a different case) so maybe the 877 is not up to ZBFW but having said that the CPU never really broke a sweat.&amp;nbsp; Speedtest just showed up and downloaded running about 25% of what they did on the classic firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is our home router so we had a chance to play but I couldn't get the performace to match the classic so we're back on that. Might be a software version thing.&amp;nbsp; I don't have smartnet so I can't test this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jun 2012 18:55:45 GMT</pubDate>
    <dc:creator>nickbrooker</dc:creator>
    <dc:date>2012-06-28T18:55:45Z</dc:date>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818430#M459924</link>
      <description>&lt;P&gt;I have a customer with an 877 series router with a zone-based firewall configuration. If they try to download anything the speed slows to a crawl and becomes almost unresponsive. I have tested with the zone pairs unapplied and it is fine. Can anyone point out what I need to remove/change from this config to improve things? Many thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818430#M459924</guid>
      <dc:creator>mbluemel</dc:creator>
      <dc:date>2019-03-11T22:25:19Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818431#M459926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If they are http downloads, you can try to remove the http inspections on your policy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-any ccp-cls-insp-traffic&lt;/P&gt;&lt;P&gt; no match protocol http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-inspect&lt;/P&gt;&lt;P&gt; no class type inspect ccp-protocol-http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, if the issue persist, you can enable the logs of Zone based to see if packets are being dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router(config)# ip inspect log drop-pkt &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then enable the logs and see what appears there, if you get drops due to straight segment mostlikely they are Out of Order packets and you will need to double check the link with your ISP. Other logs may tell you that they are indeed out of order packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason why it works with the Zone based off, is because (if the root cause is out of order and not just the inspection causing delay) the Router dont care if the packets come out of Order, it is just in charge of routing them. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 14:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818431#M459926</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2012-02-07T14:46:58Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818432#M459927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply. I am sure I have tried removing the inspection and it didnt help. I will try it again tomorrow just in case. I will let you know how I get on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 15:58:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818432#M459927</guid>
      <dc:creator>mbluemel</dc:creator>
      <dc:date>2012-02-07T15:58:20Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818433#M459929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fair enough, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep me updated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Feb 2012 16:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818433#M459929</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2012-02-07T16:17:45Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818434#M459931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried taking the http inspection rules out and had the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug messages : &lt;/P&gt;&lt;P&gt;000168: Feb&amp;nbsp; 9 14:26:06.108 gmt: %FW-6-DROP_PKT: Dropping tcp session 195.74.103.133:33032 192.168.1.1:25&amp;nbsp; due to&amp;nbsp; Out-Of-Order Segment with ip ident 0&lt;/P&gt;&lt;P&gt;000169: Feb&amp;nbsp; 9 14:26:36.156 gmt: %FW-6-DROP_PKT: Dropping tcp session 173.194.41.130:80 192.168.1.11:53846&amp;nbsp; due to&amp;nbsp; Out-Of-Order Segment with ip ident 0&lt;/P&gt;&lt;P&gt;000170: Feb&amp;nbsp; 9 14:27:06.459 gmt: %FW-6-DROP_PKT: Dropping tcp session 195.74.103.133:33032 192.168.1.1:25&amp;nbsp; due to&amp;nbsp; Out-Of-Order Segment with ip ident 0&lt;/P&gt;&lt;P&gt;000171: Feb&amp;nbsp; 9 14:27:36.823 gmt: %FW-6-DROP_PKT: Dropping tcp session 173.194.41.131:80 192.168.1.11:53823&amp;nbsp; due to&amp;nbsp; Out-Of-Order Segment with ip ident 0&lt;/P&gt;&lt;P&gt;000172: Feb&amp;nbsp; 9 14:28:08.007 gmt: %FW-6-DROP_PKT: Dropping tcp session 173.194.41.130:80 192.168.1.11:53897&amp;nbsp; due to&amp;nbsp; Out-Of-Order Segment with ip ident 0&lt;/P&gt;&lt;P&gt;000173: Feb&amp;nbsp; 9 14:28:46.336 gmt: %FW-6-DROP_PKT: Dropping tcp session 61.206.117.4:56336 192.168.1.1:25&amp;nbsp; due to&amp;nbsp; Retransmitted Segment with Invalid Flags with ip ident 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 14:33:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818434#M459931</guid>
      <dc:creator>mbluemel</dc:creator>
      <dc:date>2012-02-09T14:33:15Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818435#M459932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just what I suspected. Would you be able to contact your Carrier and check their circuit? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 20:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818435#M459932</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2012-02-09T20:47:29Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818436#M459933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike. I found this thread and think it may be the answer to my problem. I am going to try and give it a try in the next few days. I am very busy at the moment and going on leave next week so cannot guarantee it will be done next week but I will let you know how it goes. &lt;/P&gt;&lt;P&gt;&lt;A href="http://www.dslreports.com/forum/remark,24332834"&gt;http://www.dslreports.com/forum/remark,24332834&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your assistance with this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 08:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818436#M459933</guid>
      <dc:creator>mbluemel</dc:creator>
      <dc:date>2012-02-10T08:25:42Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818437#M459934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I am not mistaken, that parameter map for OoO packets is available on version 15 and higher, it may alleviate the issue, (never worked for me thou) but, if it does, then great. Let me know how it goes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 22:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818437#M459934</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2012-02-10T22:46:48Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818438#M459935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not an option to upgrade unfortunately. Not enough ram or flash on the router.&lt;/P&gt;&lt;P&gt;Looks like we will have to rebuild the router without the zone based firewall. &lt;/P&gt;&lt;P&gt;Oh well. Thanks for your input anyway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 14:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818438#M459935</guid>
      <dc:creator>mbluemel</dc:creator>
      <dc:date>2012-02-16T14:51:10Z</dc:date>
    </item>
    <item>
      <title>Zone based firewall slowing downloads</title>
      <link>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818439#M459936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I had exactly the same experience on an SR520 (basically an 877 with a different case) so maybe the 877 is not up to ZBFW but having said that the CPU never really broke a sweat.&amp;nbsp; Speedtest just showed up and downloaded running about 25% of what they did on the classic firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is our home router so we had a chance to play but I couldn't get the performace to match the classic so we're back on that. Might be a software version thing.&amp;nbsp; I don't have smartnet so I can't test this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 18:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zone-based-firewall-slowing-downloads/m-p/1818439#M459936</guid>
      <dc:creator>nickbrooker</dc:creator>
      <dc:date>2012-06-28T18:55:45Z</dc:date>
    </item>
  </channel>
</rss>

