<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA/Firepower throughput per flow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3790160#M7457</link>
    <description>&lt;P&gt;yes it will be in fastest path if it is in stateful inspection entry.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jan 2019 09:09:46 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2019-01-29T09:09:46Z</dc:date>
    <item>
      <title>Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789287#M7434</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what ist the throughput per &lt;SPAN&gt;throughput&lt;/SPAN&gt; on multicore ASA&lt;/P&gt;
&lt;P&gt;Cisco ASA ASA5585-SSP-20 1 CPU 8 Core&lt;/P&gt;
&lt;P&gt;when using 10Gbit NICs ? Each flow is handled by one core. Is there a limit per core ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:42:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789287#M7434</guid>
      <dc:creator>kerstin-534</dc:creator>
      <dc:date>2020-02-21T16:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789307#M7439</link>
      <description>&lt;P&gt;the max throughput for ASA 5585 SSP40 is 20Gbps&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BLOCK_DIAGRAM1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/28832i271CB212EB99DC68/image-size/large?v=v2&amp;amp;px=999" role="button" title="BLOCK_DIAGRAM1.PNG" alt="BLOCK_DIAGRAM1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BLOCK_DIAGRAM2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/28833i538C379689A958BD/image-size/large?v=v2&amp;amp;px=999" role="button" title="BLOCK_DIAGRAM2.PNG" alt="BLOCK_DIAGRAM2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BLOCK_DIAGRAM3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/28834iA98D4A29ABDC3242/image-size/large?v=v2&amp;amp;px=999" role="button" title="BLOCK_DIAGRAM3.PNG" alt="BLOCK_DIAGRAM3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Andrew Ossipov did a cisco live have a look BRKSEC-3021&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 11:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789307#M7439</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-28T11:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789325#M7444</link>
      <description>&lt;P&gt;yes, the Cisco Live with&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Andrew Ossipov does some clarification, the question is throughput per flow. So the box have a data-sheet throughput of 5 Gbps and 10Gbit NICs. When there is a service, eg a CIFS file service, when doing exact one transfer over the 5585-SSP20 what is the limit on the flow.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 12:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789325#M7444</guid>
      <dc:creator>kerstin-534</dc:creator>
      <dc:date>2019-01-28T12:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789333#M7449</link>
      <description>&lt;P&gt;I think the best answer we could get is from cisco tac.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 12:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789333#M7449</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-28T12:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789626#M7451</link>
      <description>&lt;P&gt;Are you using the Firepower module? If so, the limiting factor will be that a given flow (5-tuple) is tied to a single Snort process.&amp;nbsp;A Snort process is limited to something like 500 Mbps per instance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/200420-Processing-of-Single-Stream-Large-Sessio.html#anc6" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/200420-Processing-of-Single-Stream-Large-Sessio.html#anc6&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 17:30:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3789626#M7451</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-01-28T17:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3790138#M7454</link>
      <description>&lt;P&gt;No, without Firepower. Simple one TCP connection through ASA in the fastest path.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 08:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3790138#M7454</guid>
      <dc:creator>kerstin-534</dc:creator>
      <dc:date>2019-01-29T08:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3790160#M7457</link>
      <description>&lt;P&gt;yes it will be in fastest path if it is in stateful inspection entry.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 09:09:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3790160#M7457</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-29T09:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3791056#M7459</link>
      <description>&lt;P&gt;I asked Andrew Ossipov directly at Cisco Live Barcelona today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;He told me that on an ASA 5585-X (non-Firepower), the single flow throughput limit is 3-4 Gbps (TCP) or 6-8 Gbps (UDP).&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 10:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3791056#M7459</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-01-30T10:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3791057#M7460</link>
      <description>&lt;P&gt;nice one Marvin thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 10:26:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3791057#M7460</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-30T10:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3791069#M7463</link>
      <description>&lt;P&gt;thank you, Marvin&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 10:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/3791069#M7463</guid>
      <dc:creator>kerstin-534</dc:creator>
      <dc:date>2019-01-30T10:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/4557630#M1087603</link>
      <description>&lt;P&gt;We are opening up a Case with Cisco TAC shortly.&amp;nbsp; We did some performance testing on single nuttcp flows with the Cisco 5585-X and got limited to 2.9 Gb/s for a single TCP Flow.&amp;nbsp;&amp;nbsp; Please advise on your reference on (non-Firepower).&amp;nbsp; We have Model ASA5585-SSP-60 running 9.8(4)40.&amp;nbsp;&amp;nbsp; The SPEC sheet for the 5585-X is 20 Gbps for NON-VPN multi protocol for total throughput , so its odd that a single flow is limited to 2.9Gbps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 22:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/4557630#M1087603</guid>
      <dc:creator>netadmin4</dc:creator>
      <dc:date>2022-02-22T22:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/4557755#M1087606</link>
      <description>&lt;P&gt;As I noted in my posting from 30 January 2019, the expected maximum throughput for a single TCP session is 3-4 Gbps. So, if you are getting 2.9 Gbps, I wouldn't expect any more than that. The 20 Gbps number is the expected maximum across multiple sessions/flows, TCP and UDP, from multiple hosts to multiple hosts.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 07:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/4557755#M1087606</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-02-23T07:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/4560800#M1087761</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response on this.&amp;nbsp; The Cisco TAC didn't provide any definitive SPECS for the ASA 5585X-SSP-60 hardware yet.&amp;nbsp; However, we tested our new FPR9K with SM-56 which should be capable of 10 Gbps on single Flow and only got 6 Gbps.&amp;nbsp; On further review we found that the MSS without it being properly tuned/configured for Jumbo frames is limited to 1380 (1368).&amp;nbsp; By setting it on the FPR9k via the command: sysopt connection tcpmss 0, it allowed a higher MSS of 8948 to take advantage of our 9K Jumbo Frames MTU. We then got over 9 Gbps on the FPR9K.&amp;nbsp; Setting the same sysopt command on the 5585-X with SSP-60&amp;nbsp; it then boosted the single flow performance to 8 Gbps. All tested with the Nuttcp tool.&amp;nbsp; &lt;A href="https://www.nuttcp.net/Welcome%20Page.html" target="_blank"&gt;https://www.nuttcp.net/Welcome%20Page.html&lt;/A&gt; and Linux servers with 10Gb NICs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V/R&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 15:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/4560800#M1087761</guid>
      <dc:creator>netadmin4</dc:creator>
      <dc:date>2022-02-28T15:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA/Firepower throughput per flow</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/4560801#M1087762</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response on this.&amp;nbsp; The Cisco TAC didn't provide any definitive SPECS for the ASA 5585X-SSP-60 hardware yet.&amp;nbsp; However, we tested our new FPR9K with SM-56 which should be capable of 10 Gbps on single Flow and only got 6 Gbps.&amp;nbsp; On further review we found that the MSS without it being properly tuned/configured for Jumbo frames is limited to 1380 (1368).&amp;nbsp; By setting it on the FPR9k via the command: sysopt connection tcpmss 0, it allowed a higher MSS of 8948 to take advantage of our 9K Jumbo Frames MTU. We then got over 9 Gbps on the FPR9K.&amp;nbsp; Setting the same sysopt command on the 5585-X with SSP-60&amp;nbsp; it then boosted the single flow performance to 8 Gbps. All tested with the Nuttcp tool.&amp;nbsp; &lt;A href="https://www.nuttcp.net/Welcome%20Page.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.nuttcp.net/Welcome%20Page.html&lt;/A&gt; and Linux servers with 10Gb NICs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V/R&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 15:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-firepower-throughput-per-flow/m-p/4560801#M1087762</guid>
      <dc:creator>netadmin4</dc:creator>
      <dc:date>2022-02-28T15:30:51Z</dc:date>
    </item>
  </channel>
</rss>

