<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIM-IPS Performance Limits? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642380#M65916</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;several factors can limit throughput:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- make sure you are on a recent release on the ips module to make sure you have the latest performance tweaks.&lt;/P&gt;&lt;P&gt;2- check cpu inspection load on the ips module:&lt;/P&gt;&lt;P&gt;sh statistics virtual-sensor | inc Load&lt;/P&gt;&lt;P&gt; if it's very high this will limit throughput and you'll need to tweak your current set of signatures to be less busy.&lt;/P&gt;&lt;P&gt;3- make sure the router side is also not having performance issues (check "show proc cpu").&lt;/P&gt;&lt;P&gt;4- are there any features configured on the router side that could be cpu intensive? like zone based firewall, tcp settings etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Fadi.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Dec 2010 10:54:56 GMT</pubDate>
    <dc:creator>fadlouni</dc:creator>
    <dc:date>2010-12-27T10:54:56Z</dc:date>
    <item>
      <title>AIM-IPS Performance Limits?</title>
      <link>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642379#M65915</link>
      <description>&lt;P&gt;&lt;!--StartFragment--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;We are using an AIM-IPS module in a 1841 and it has been working fine, however we just upgraded our broadband link and didn’t notice a increase in throughput.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;We were consistently getting about 16 meg download speeds and this didn’t change with the new service tier.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Removing the IPS module (no ids-service module monitoring inline) does give us the new speeds (35+ meg down) &lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;I thought the AIM-IPS module had a limit of 45 meg throughput, before I trouble shoot more, shouldn’t I expect throughput closer to the 45 meg limit? &lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;!--EndFragment--&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:13:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642379#M65915</guid>
      <dc:creator>kstarnes11</dc:creator>
      <dc:date>2019-03-10T12:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: AIM-IPS Performance Limits?</title>
      <link>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642380#M65916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;several factors can limit throughput:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- make sure you are on a recent release on the ips module to make sure you have the latest performance tweaks.&lt;/P&gt;&lt;P&gt;2- check cpu inspection load on the ips module:&lt;/P&gt;&lt;P&gt;sh statistics virtual-sensor | inc Load&lt;/P&gt;&lt;P&gt; if it's very high this will limit throughput and you'll need to tweak your current set of signatures to be less busy.&lt;/P&gt;&lt;P&gt;3- make sure the router side is also not having performance issues (check "show proc cpu").&lt;/P&gt;&lt;P&gt;4- are there any features configured on the router side that could be cpu intensive? like zone based firewall, tcp settings etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Fadi.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 10:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642380#M65916</guid>
      <dc:creator>fadlouni</dc:creator>
      <dc:date>2010-12-27T10:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: AIM-IPS Performance Limits?</title>
      <link>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642381#M65917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Ok thanks for the tips - I will do some more investigation.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;It is running a zone based firewall, but by just removing the "ids-service module" lines I saw a decent gain in throughput.&lt;/P&gt;&lt;P class="MsoNormal"&gt;That is, zone firewall still configured but with no ids module: we were getting the expected speeds.&amp;nbsp; I was thinking that while the module might add a little latency, since it had its own CPU/Memory it shouldn't cause such a degradation.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;I will do some more testing/monitoring - I guess I really wanted to make sure that the ids module was capable of faster performance than I was seeing (i.e. I wasn't troubleshooting a performance problem that wasn't really a problem but was within spec for the device)&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Dec 2010 19:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642381#M65917</guid>
      <dc:creator>kstarnes11</dc:creator>
      <dc:date>2010-12-27T19:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: AIM-IPS Performance Limits?</title>
      <link>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642382#M65918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;Ok a little more details:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;IPS Software: 7.0(4) E4&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I removed the zone firewall and all VPN configuration from the router and now have a 1841 with a pretty minimal config.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;With only NAT, no firewall, no routing protocols, no IPS - it runs a pretty constant 60Mbits throughput between a inside and outside host (using iperf)&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Insert the ids-service-module monitor into either (or both interfaces) and the throughput drops from 60Mbits to 20Mbits.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Interestingly the throughput stays the same even with both FastEthernet interfaces configured for the IPS.&amp;nbsp; i.e. It never drops below 20Mbits.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;The router CPU is @ 85% (with and without the IPS enabled)&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;The IPS module inspection load is constant at about 22%&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Any thoughts?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Thanks!!&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 03:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aim-ips-performance-limits/m-p/1642382#M65918</guid>
      <dc:creator>kstarnes11</dc:creator>
      <dc:date>2010-12-28T03:03:21Z</dc:date>
    </item>
  </channel>
</rss>

