<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PPTP performance through ASA5520 very poor in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795885#M493358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mainly on the ASA... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you use this VPN connection to go to the internet? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Nov 2011 02:50:15 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2011-11-15T02:50:15Z</dc:date>
    <item>
      <title>PPTP performance through ASA5520 very poor</title>
      <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795882#M493355</link>
      <description>&lt;P&gt;We use MS RRAS services behind a Cisco ASA 5520. In testing the performance I have found that we can only get a little over 2MB of througput when connected to the VPN server over a broadband connection. I have verified that the issue is not the RRAS server itself as I can connect to VPN from the LAN and the througput tests at 300-400MB. I also connected to the LAN directly on the outside of the firewall and only get 4 or 5 MB from there which does not seem right. None of the switches are showing any errors. I believe that I have the passthrough stuff setup as I should. I even went through these steps as recommended by Cisco. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# class-map pptp-port&lt;/P&gt;&lt;P&gt;hostname(config-cmap)# match port tcp eq 1723&lt;/P&gt;&lt;P&gt;hostname(config-cmap)# exit&lt;/P&gt;&lt;P&gt;hostname(config)# policy-map pptp_policy&lt;/P&gt;&lt;P&gt;hostname(config-pmap)# class pptp-port&lt;/P&gt;&lt;P&gt;hostname(config-pmap-c)# inspect pptp&lt;/P&gt;&lt;P&gt;hostname(config-pmap-c)# exit&lt;/P&gt;&lt;P&gt;hostname(config)# service-policy pptp_policy interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insight is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795882#M493355</guid>
      <dc:creator>mabouchard</dc:creator>
      <dc:date>2019-03-11T21:50:22Z</dc:date>
    </item>
    <item>
      <title>PPTP performance through ASA5520 very poor</title>
      <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795883#M493356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you getting the same low throughput for regular connections across the ASA? If this is only happening when using PPTP, it may suggest a problem with MTU (cuz of the overhead that GRE causes to the packets). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 01:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795883#M493356</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-15T01:10:44Z</dc:date>
    </item>
    <item>
      <title>PPTP performance through ASA5520 very poor</title>
      <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795884#M493357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The throughput on the firewall seems to be fine. I have not tested it by just NATing a public address to private but doing bandwidth testing we are getting ~70MB on a 100MB pipe. When you are referring to MTU are you talking about on the firewall or on the RRAS server, or both?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 01:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795884#M493357</guid>
      <dc:creator>mabouchard</dc:creator>
      <dc:date>2011-11-15T01:15:31Z</dc:date>
    </item>
    <item>
      <title>PPTP performance through ASA5520 very poor</title>
      <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795885#M493358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mainly on the ASA... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you use this VPN connection to go to the internet? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 02:50:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795885#M493358</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-15T02:50:15Z</dc:date>
    </item>
    <item>
      <title>PPTP performance through ASA5520 very poor</title>
      <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795886#M493359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes,&lt;/P&gt;&lt;P&gt; It is our main Internet firewall and also used for client VPN access. I have read that RRAS has some dynamic MTU negotiation that can supposedly be set to not do the negotiation but not sure if that will help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 02:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795886#M493359</guid>
      <dc:creator>mabouchard</dc:creator>
      <dc:date>2011-11-15T02:55:19Z</dc:date>
    </item>
    <item>
      <title>PPTP performance through ASA5520 very poor</title>
      <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795887#M493361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I am concern about is the Overhead that NAT and GRE can cause to the packets, hence making the packet to big and the firewall has to fragment it.... Have you changed the MTU on the ASA? Can you run a capture inside and outside of the firewall to see how big the packets are? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 03:19:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795887#M493361</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-15T03:19:01Z</dc:date>
    </item>
    <item>
      <title>PPTP performance through ASA5520 very poor</title>
      <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795888#M493363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I verified that MTU on the outside interface of the ASA was 1500. I will need to look at doing a packet capture. From what I understand 1500 is as high as you can go on a 5520? What would a solution be if they were larger than that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 04:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795888#M493363</guid>
      <dc:creator>mabouchard</dc:creator>
      <dc:date>2011-11-15T04:04:01Z</dc:date>
    </item>
    <item>
      <title>PPTP performance through ASA5520 very poor</title>
      <link>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795889#M493364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont really think they would be... The captures need to be on both interfaces... inside and outside, here is an example. Here is the link on how to configure the captures...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1222"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 05:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-performance-through-asa5520-very-poor/m-p/1795889#M493364</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-11-15T05:05:13Z</dc:date>
    </item>
  </channel>
</rss>

