<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA performance? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548424#M608799</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rya,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;650 Mbps is the 5540's native max throughput. With the AIP SSM-20 installed this drops a bit to about 500 Mbps, however using an AIP SSM-40 will support up to 650 Mbps throughput as well. This document has more details (see Table 4):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind, though, that these numbers are only achievable&amp;nbsp; in very ideal cases. In real world scenarios with varying traffic profiles, your throughput may be considerably lower.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Oct 2010 18:08:47 GMT</pubDate>
    <dc:creator>mirober2</dc:creator>
    <dc:date>2010-10-19T18:08:47Z</dc:date>
    <item>
      <title>Cisco ASA performance?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548423#M608798</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the Cisco ASA 5540 the advertised throughput for that model is up to 650Mbps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean the firewall natively can handle Firewall throughput up to 650Mbps without AIP-SSM modules? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is the AIP-SSM modules required to support up to 650Mbps where the firewall (and IPS) workload is off-loaded to the SSM module?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- rya&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:56:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548423#M608798</guid>
      <dc:creator>ryabutler</dc:creator>
      <dc:date>2019-03-11T18:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA performance?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548424#M608799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rya,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;650 Mbps is the 5540's native max throughput. With the AIP SSM-20 installed this drops a bit to about 500 Mbps, however using an AIP SSM-40 will support up to 650 Mbps throughput as well. This document has more details (see Table 4):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind, though, that these numbers are only achievable&amp;nbsp; in very ideal cases. In real world scenarios with varying traffic profiles, your throughput may be considerably lower.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 18:08:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548424#M608799</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-10-19T18:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA performance?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548425#M608800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ryabutler wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the Cisco ASA 5540 the advertised throughput for that model is up to 650Mbps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean the firewall natively can handle Firewall throughput up to 650Mbps without AIP-SSM modules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is the AIP-SSM modules required to support up to 650Mbps where the firewall (and IPS) workload is off-loaded to the SSM module?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- rya&lt;/P&gt;&lt;PRE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the datasheet -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="1" cellpadding="6" cellspacing="0" id="wp9000072table4000004" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;A name="wp9000074"&gt;&lt;/A&gt;&lt;P class="pChart_subheadCMT" style="text-align: left; text-transform: none; font-variant: normal; font-style: normal; text-indent: 0pt; margin: 3pt; text-decoration: none;"&gt;&lt;EM&gt;Firewall Throughput&lt;/EM&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp9000075"&gt;&lt;/A&gt;&lt;P class="pChart_bodyCMT" style="text-align: left; text-transform: none; font-variant: normal; font-style: normal; text-indent: 0pt; margin: 3pt; font-weight: normal; text-decoration: none;"&gt;&lt;EM&gt;Up to 650 Mbps&lt;/EM&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;A name="wp9000076"&gt;&lt;/A&gt;&lt;P class="pChart_subheadCMT" style="text-align: left; text-transform: none; font-variant: normal; font-style: normal; text-indent: 0pt; margin: 3pt; text-decoration: none;"&gt;&lt;EM&gt;Maximum Firewall and IPS Throughput&lt;/EM&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp9000077"&gt;&lt;/A&gt;&lt;DIV class="pCellBulletCMT" style="text-align: left; text-transform: none; font-variant: normal; font-style: normal; margin-top: 3pt; margin-bottom: 3pt; font-weight: normal; margin-right: 3pt; text-decoration: none;"&gt;&lt;EM&gt;• Up to 500 Mbps with AIP SSM-20&lt;/EM&gt;&lt;/DIV&gt;&lt;A name="wp9000078"&gt;&lt;/A&gt;&lt;DIV class="pCellBulletCMT" style="text-align: left; text-transform: none; font-variant: normal; font-style: normal; margin-top: 3pt; margin-bottom: 3pt; font-weight: normal; margin-right: 3pt; text-decoration: none;"&gt;&lt;EM&gt;• Up to 650 Mbps with AIP SSM-40&lt;/EM&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;so the 650Mbps is pure firewalling throughput on cleartext traffic. If you want to use combine IPS with your firewall then you can use an AIP SSM card and then the combined firewall/IPS throughput is either 500 or 650Mbps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 18:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548425#M608800</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-10-19T18:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA performance?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548426#M608801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, that makes sense so FW+IPS throughput can be handled on the SSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about VPN using AES.&amp;nbsp; A single site VPN tunnel.&amp;nbsp; The ASA 5540 supports up to 325Mbps throughput when using AES/3DES.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming this is handled natively on the ASA since I do see anywhere that the SSM offload VPN encryption/descyption operations?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if I am running all three of those services is my best possible throughput through that ASA model at least 325Mbps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- rya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 23:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548426#M608801</guid>
      <dc:creator>ryabutler</dc:creator>
      <dc:date>2010-10-19T23:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA performance?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548427#M608802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="padding-left: 30px;"&gt;Hi Rya,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;The SSM is not used to offload processing and boost throughput. The reason that there are different throughput numbers when using an SSM is because the added packet processing adds a bit of delay to the connection (the packets go through extra security checks by the AIP module, in addition to the ones done by the ASA, and this takes time). Likewise, throughput drops a bit when using VPN/encryption because of the added overhead of encrypting/decrypting the packets for the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;As I mentioned though, these numbers are only an ideal value. So if you are encrypting/decrypting traffic for a VPN and inspecting it with an SSM, your throughput will likely be much lower than the advertised ideal values. Just be sure that you plan for this in your deployment and choose the hardware and configuration that will give you room to scale in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px; text-align: left;"&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 12:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-performance/m-p/1548427#M608802</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-10-20T12:57:34Z</dc:date>
    </item>
  </channel>
</rss>

