<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Throughput when load balancing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573940#M610092</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Having looked at the specifications for the ASA-5520 on this page here (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html&lt;/A&gt;&lt;SPAN&gt;) I have the following key facts:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA 5520 Firewall Throughput: &lt;STRONG&gt;Up to 450Mbps&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Maximum Firewall and IPS Throughput (SSM-20): &lt;STRONG&gt;Up to 375Mbps&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I were to run two ASA-5520s as a failover pair, and also load balance between them, would the maximum throughput potentially be &lt;STRONG&gt;900Mbps (750Mbps with IPS)&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently running an Active/Standby configuration between two &lt;STRONG&gt;1Gbps &lt;/STRONG&gt;LAN environments.&amp;nbsp; However the firewall has become a bottleneck.&amp;nbsp; If we were to upgrade this to an Active/Active configuration we believe this would give us much better throughput.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What load balancing methodologies would people advise?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:48:21 GMT</pubDate>
    <dc:creator>adsyparker</dc:creator>
    <dc:date>2019-03-11T18:48:21Z</dc:date>
    <item>
      <title>ASA Throughput when load balancing</title>
      <link>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573940#M610092</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Having looked at the specifications for the ASA-5520 on this page here (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html" target="_blank"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html&lt;/A&gt;&lt;SPAN&gt;) I have the following key facts:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA 5520 Firewall Throughput: &lt;STRONG&gt;Up to 450Mbps&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Maximum Firewall and IPS Throughput (SSM-20): &lt;STRONG&gt;Up to 375Mbps&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I were to run two ASA-5520s as a failover pair, and also load balance between them, would the maximum throughput potentially be &lt;STRONG&gt;900Mbps (750Mbps with IPS)&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently running an Active/Standby configuration between two &lt;STRONG&gt;1Gbps &lt;/STRONG&gt;LAN environments.&amp;nbsp; However the firewall has become a bottleneck.&amp;nbsp; If we were to upgrade this to an Active/Active configuration we believe this would give us much better throughput.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What load balancing methodologies would people advise?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573940#M610092</guid>
      <dc:creator>adsyparker</dc:creator>
      <dc:date>2019-03-11T18:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Throughput when load balancing</title>
      <link>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573941#M610093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please kindly be advised that ASA in Active/Active failover mode does not support traffic load balancing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Active/Active mode needs to be in multiple context mode, and you can have some context active on first ASA and some other context active on second ASA, however, you can not just load balance traffic within the same context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 10:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573941#M610093</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-01T10:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Throughput when load balancing</title>
      <link>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573942#M610094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that we would need to move from Single Context to Multiple Context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However does this allow me to simply have the contexts be exact replica's of each other?&amp;nbsp; For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA1: Context-A Active, Context-B Standby&lt;/P&gt;&lt;P&gt;ASA2: Context-A Standby, Context-B Active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where Context A and Context B hold identical firewall rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 10:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573942#M610094</guid>
      <dc:creator>adsyparker</dc:creator>
      <dc:date>2010-10-01T10:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Throughput when load balancing</title>
      <link>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573943#M610095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can have the exact rules, however, you can't have the exact same subnet/interfaces.&lt;/P&gt;&lt;P&gt;Those 2 contexts (Context-A and Context-B) needs to be virtually a separate FW unfortunately. That's why I said, it's not load balancing traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 11:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573943#M610095</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-01T11:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Throughput when load balancing</title>
      <link>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573944#M610096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply Jennifer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand we would have to IP address two separate virtual firewalls (two subnets on the outside, and two on the inside).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Eg for the Outside configuration only:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ASA1 (&lt;STRONG&gt;Context A active&lt;/STRONG&gt;, Context B standby):&lt;/P&gt;&lt;P&gt;ASA2 (Context A standby, &lt;STRONG&gt;Context B active&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Context A&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Active IP = 192.168.3.1&lt;/P&gt;&lt;P&gt;Standby IP = 192.168.3.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Context B&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Active IP = 192.168.4.1&lt;/P&gt;&lt;P&gt;Standby IP = 192.168.4.2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Assume there are two switches, both trunked to each other and each with a single connection to a firewall.&amp;nbsp; We could then use static routes from the Outside switches to the inside:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1---SW2&amp;nbsp; - Outside&lt;/P&gt;&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;ASA1---ASA2&lt;/P&gt;&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;SW3---SW4&amp;nbsp; - Inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would involve a lot of static routing as dynamic protocols are out in multicontext Active/Active configurations, but I believe it is possible to implement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;A&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 15:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573944#M610096</guid>
      <dc:creator>adsyparker</dc:creator>
      <dc:date>2010-10-01T15:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Throughput when load balancing</title>
      <link>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573945#M610097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you are right. If they are completely separate context, you can definitely configure as per your diagram.&lt;/P&gt;&lt;P&gt;Common scenario would be managing multiple customers through the same physical ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Example&lt;/STRONG&gt;&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;If you are managing 5 customers --&amp;gt; 5 contexts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA1&lt;/STRONG&gt;: &lt;STRONG&gt;Context-A&lt;/STRONG&gt; (Active),&lt;STRONG&gt; Context-B&lt;/STRONG&gt; (Active), &lt;STRONG&gt;Context-C&lt;/STRONG&gt; (Active), Context-D (Standby) and Context-E (Standby)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA2&lt;/STRONG&gt;: Context-A (Standby), Context-B (Standby), Context-C (Standby), &lt;STRONG&gt;Context-D&lt;/STRONG&gt; (Active) and &lt;STRONG&gt;Context-E&lt;/STRONG&gt; (Active)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you would need to make sure is if one or the other ASA fails, the one ASA needs to be able to cope with the load for 5 contexts.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Say ASA-1 fails, ASA-2 has to be able to cope with all the 5 context being active on it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Oct 2010 05:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573945#M610097</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-02T05:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Throughput when load balancing</title>
      <link>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573946#M610098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"however, you can not just load balance traffic within the same context"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you stated above is "technically" correct for existing code.&amp;nbsp; However, with the upcoming release of new ASA code, code name "spiker", you WILL be able to load balancing traffics within the same context.&amp;nbsp; At least, that's what I was told by a Cisco SE when I asked him about load-balancing.&amp;nbsp; Currently&lt;/P&gt;&lt;P&gt;ASA load balancing is nothing but a gimmick.&amp;nbsp; In other words, it is similarly to running multiple HSRP group in IOS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, Checkpoint has been doing load balancing within the same context for years with IPSO clustering or ClusterXL for years.&amp;nbsp; I am glad to see Cisco is finally recognizing this.&amp;nbsp; This will make things much easier for customers to migrate from Checkpoint over Cisco ASA platforms.&amp;nbsp; If "spiker" can also add GRE tunnel to the ASA, that will be even better.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Oct 2010 13:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-throughput-when-load-balancing/m-p/1573946#M610098</guid>
      <dc:creator>cciesec2011</dc:creator>
      <dc:date>2010-10-02T13:41:05Z</dc:date>
    </item>
  </channel>
</rss>

