<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM 20 Throughput  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111486#M78855</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the throughput of the AIP-SSM20 on the 5520 as per Cicso:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;375 (with AIP SSM-20)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can monitor the ammount of data being sent to the IPS via snmp etc. and double check this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you need to re-think your capture ACL used to send traffic to the IPS module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Sep 2008 06:11:47 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-09-04T06:11:47Z</dc:date>
    <item>
      <title>AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111485#M78854</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are in process of installing the AIP-SSM20 modules in ASA5520 (Active/passive). Currently its configured in promiscuous mode /w monitoring all the outside and dmz traffic... I have also tuned various signature to troubleshoot and increase the AIP-SSM20 throughput but I am seeing below messages randomly throughout the day:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evStatus: eventId=1218593040808071564  vendor=Cisco  &lt;/P&gt;&lt;P&gt;  originator:   &lt;/P&gt;&lt;P&gt;    hostId: caipssm01waynpa  &lt;/P&gt;&lt;P&gt;    appName: interface  &lt;/P&gt;&lt;P&gt;    appInstanceId: 340  &lt;/P&gt;&lt;P&gt;  time: Sep 03, 2008 20:19:16 UTC  offset=-240  timeZone=GMT-05:00  &lt;/P&gt;&lt;P&gt;  netInterfaceMissedPacketThresholdExceeded:   &lt;/P&gt;&lt;P&gt;    description: GigabitEthernet0/1 : Missed-packet threshold was exceeded.  3% of packets were missed.  &lt;/P&gt;&lt;P&gt;    interfaceName: GigabitEthernet0/1  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering if anyone had ran into this issue... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running 6.1.1E2 and ASA OS  7.2.1...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate any help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank in a advance&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111485#M78854</guid>
      <dc:creator>msdesai</dc:creator>
      <dc:date>2019-03-10T11:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111486#M78855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the throughput of the AIP-SSM20 on the 5520 as per Cicso:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;375 (with AIP SSM-20)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can monitor the ammount of data being sent to the IPS via snmp etc. and double check this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you need to re-think your capture ACL used to send traffic to the IPS module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2008 06:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111486#M78855</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-09-04T06:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111487#M78856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Farrukh for quick response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know any snmp monitoring tool that I can use to monitor the amount of data being sent to the IPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think we are getting 375M throughput but I can't say by sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2008 16:40:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111487#M78856</guid>
      <dc:creator>msdesai</dc:creator>
      <dc:date>2008-09-04T16:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111488#M78857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm doubtfull that the orginal poster is running his sensor anywhere near the "offical" throughtput limit.&lt;/P&gt;&lt;P&gt;Cisco's IPS throughput numbers are fantasy.&lt;/P&gt;&lt;P&gt;With real world traffic we begin to see those missed packet percentage (along with 100% CPU utilization at about 1/3 of the Cisco rated throughput numbers. Keep in mind that Cisco always adds both directions of traffic together to get their whole number, so if they rate a SSM-20 module in a ASA 5520 for 375 Mb/s you can expect about 125 Mb/s or a little better than a DS-3 worth of IPS functionality. If you want to verify this at home, load up your sensor with some FTP sessions and see when your CPU hits 100% and you start getting missed packet % events.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2008 17:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111488#M78857</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-09-04T17:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111489#M78858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MRTG will work, as would any SNMP pooler.&lt;/P&gt;&lt;P&gt;For somthing qucik, you can use the GUI in the IDM, or pull the stats out of the CLI using the "show status analysis" and "show status interface" commands. A little math is involved in using the CLI show interface command to determine bandwidth numbers: request the stats 60 seconds apart, subtract the first B/s number from the second, devide by 60 (seconds) and multiply by 8 (Bytes to Bits)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2008 20:19:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111489#M78858</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-09-04T20:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111490#M78859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. I have configured the MRTG and monitoring the Gig0/1 interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2008 20:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111490#M78859</guid>
      <dc:creator>msdesai</dc:creator>
      <dc:date>2008-09-05T20:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111491#M78860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After monitoring for few hours. I am getting the Missed packets events with MRTG showing 11M traffic on Gig0/1 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evStatus: eventId=1218593040808080769  vendor=Cisco  &lt;/P&gt;&lt;P&gt;  originator:   &lt;/P&gt;&lt;P&gt;    hostId: caipssm01  &lt;/P&gt;&lt;P&gt;    appName: interface  &lt;/P&gt;&lt;P&gt;    appInstanceId: 340  &lt;/P&gt;&lt;P&gt;  time: Sep 05, 2008 22:05:46 UTC  offset=-240  timeZone=GMT-05:00  &lt;/P&gt;&lt;P&gt;  netInterfaceMissedPacketThresholdExceeded:   &lt;/P&gt;&lt;P&gt;    description: GigabitEthernet0/1 : Missed-packet threshold was exceeded.  14% of packets were missed.  &lt;/P&gt;&lt;P&gt;    interfaceName: GigabitEthernet0/1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MRTG Graph data:&lt;/P&gt;&lt;P&gt;day&lt;/P&gt;&lt;P&gt;	Max 	Average 	Current&lt;/P&gt;&lt;P&gt;In 	1414.9 kB/s (3.2%) 	816.5 kB/s (1.9%) 	1227.9 kB/s (2.8%)&lt;/P&gt;&lt;P&gt;Out 	1415.0 kB/s (3.2%) 	816.5 kB/s (1.9%) 	1227.9 kB/s (2.8%) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like I am not even getting 88Mbs throughput with AIP-SSM20 module. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any recommendation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in a advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2008 21:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111491#M78860</guid>
      <dc:creator>msdesai</dc:creator>
      <dc:date>2008-09-05T21:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111492#M78861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow! That is a TERRIBLE performance number.&lt;/P&gt;&lt;P&gt;What is your CPU utilization?&lt;/P&gt;&lt;P&gt;If I take your MRTG peak values, I come up with 22.6 Mb/s of inspection traffic.&lt;/P&gt;&lt;P&gt;I assume you are using the stock Cisco signature settings. You can inprove your performance slightly by disabling the uselss noisy signatures (determined by performing analysis) and placing the sensor inside your firewall to reduce the event count. This typically does not make a significate imporvement. You will not be able to double your performance.&lt;/P&gt;&lt;P&gt;You DID keep your reciept for those sensors, right?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 17:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111492#M78861</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-09-09T17:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111493#M78862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was not monitoring the CPU usage when the inspection load hit 100%. But I will enable the CPU monitoring in MRTG. Also correct numbers for the MRTG peak are below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The statistics were last updated Friday, 5 September 2008 at 23:40,&lt;/P&gt;&lt;P&gt;at which time 'caipssm01waynpa' had been up for 11 days, 5:35:38. &lt;/P&gt;&lt;P&gt;`Daily' Graph (5 Minute Average)&lt;/P&gt;&lt;P&gt;  Max Average Current &lt;/P&gt;&lt;P&gt;In 11.9 MB/s (27.2%) 797.7 kB/s (1.8%)  337.2 kB/s (0.8%)  &lt;/P&gt;&lt;P&gt;Out 11.9 MB/s (27.2%)  797.9 kB/s (1.8%)  337.2 kB/s (0.8%)  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which come up with 88Mbps. I have tried disabling few signature but no significant performance gain..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, we do have the receipt for the sensors but we bought this more then six months ago..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if anyone else ran into similar issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Sep 2008 19:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111493#M78862</guid>
      <dc:creator>msdesai</dc:creator>
      <dc:date>2008-09-10T19:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM 20 Throughput</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111494#M78863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have ASA5540 with SSM20's installed and have experienced these issues as well.  The dropped packets on the int gig0/1 are definitely indicative of performance issues.  Look for "total receive errors" &amp;amp; "total receive FIFO overruns" to also help determine if you are sending so much traffic that you are overwhelming (oversubscribing) the SSM.  Cisco TAC did advise me to use ACL's to tune out any known streaming video (we have camera traffic) as well as any IPSEC (the SSM's can't do much with encrypted traffic, so might as well not send this through this inspection.)  This will help some with the load, if you are running this traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Sep 2008 21:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-20-throughput/m-p/1111494#M78863</guid>
      <dc:creator>michael.stephen</dc:creator>
      <dc:date>2008-09-10T21:57:57Z</dc:date>
    </item>
  </channel>
</rss>

