<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Slow inbound http, fast outbound http - ASA5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/slow-inbound-http-fast-outbound-http-asa5510/m-p/1505340#M615551</link>
    <description>&lt;P&gt;Hiyas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently purchased an ASA 5510 and i'm having a slight problem configuring it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I enable the following (just default traffic inspection), download speed drops to ~ 3Mb/s from &amp;gt; 10Mb/s.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;class-map global-class&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map global-policy&lt;BR /&gt; class global-class&lt;BR /&gt;&amp;nbsp; inspect ctiqbe&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect http&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect icmp error&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;&amp;nbsp; inspect ils&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect pptp&lt;BR /&gt;&amp;nbsp; inspect dns&lt;BR /&gt;&amp;nbsp; inspect mgcp&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect snmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global-policy global&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Only HTTP traffic is affected, FTP still goes at the full 10Mb/s up and !0MB/s down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I disable the above service policy rule, everything goes fast again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone can help or provide any insight here it would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:18:29 GMT</pubDate>
    <dc:creator>mjacobsecaq</dc:creator>
    <dc:date>2019-03-11T19:18:29Z</dc:date>
    <item>
      <title>Slow inbound http, fast outbound http - ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/slow-inbound-http-fast-outbound-http-asa5510/m-p/1505340#M615551</link>
      <description>&lt;P&gt;Hiyas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently purchased an ASA 5510 and i'm having a slight problem configuring it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I enable the following (just default traffic inspection), download speed drops to ~ 3Mb/s from &amp;gt; 10Mb/s.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;class-map global-class&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map global-policy&lt;BR /&gt; class global-class&lt;BR /&gt;&amp;nbsp; inspect ctiqbe&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect http&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect icmp error&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;&amp;nbsp; inspect ils&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect pptp&lt;BR /&gt;&amp;nbsp; inspect dns&lt;BR /&gt;&amp;nbsp; inspect mgcp&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect snmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global-policy global&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Only HTTP traffic is affected, FTP still goes at the full 10Mb/s up and !0MB/s down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I disable the above service policy rule, everything goes fast again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone can help or provide any insight here it would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-inbound-http-fast-outbound-http-asa5510/m-p/1505340#M615551</guid>
      <dc:creator>mjacobsecaq</dc:creator>
      <dc:date>2019-03-11T19:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Slow inbound http, fast outbound http - ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/slow-inbound-http-fast-outbound-http-asa5510/m-p/1505341#M615552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you enable the inspection for HTTP, that will slow down the HTTP traffic a little because it is performing deep packet inspection for HTTP traffic.&lt;/P&gt;&lt;P&gt;For more details on what "inspect http" does, please check the following command reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i2.html#wp1735782"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i2.html#wp1735782&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can temporarily disable only the HTTP inspection from the global policy map as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; class global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no inspect http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above will disable just the HTTP inspection, and you can check the speed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more security, you would need to enable the http inspection, however, with security as it needs to inspect the packet in more details, it will impact the performance/speed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Dec 2010 06:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-inbound-http-fast-outbound-http-asa5510/m-p/1505341#M615552</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-12-06T06:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Slow inbound http, fast outbound http - ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/slow-inbound-http-fast-outbound-http-asa5510/m-p/1505342#M615553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer Jennifer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assumed this would be the case, but a 70% reduction in throughput just seemed a little high to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 06:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/slow-inbound-http-fast-outbound-http-asa5510/m-p/1505342#M615553</guid>
      <dc:creator>mjacobsecaq</dc:creator>
      <dc:date>2010-12-09T06:46:01Z</dc:date>
    </item>
  </channel>
</rss>

