<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP flow get slower with IPS 4255 5.1(3) in inline mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541847#M92566</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is expected.&lt;/P&gt;&lt;P&gt;Disable TCP sequence randomization on the PIX ("norandomseq") for traffic between the vlans. If it doesn't help then add "produce alert" action to the signatures in the Normalizer engine and see which signatures are firing. Then post your results here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Aug 2006 08:48:08 GMT</pubDate>
    <dc:creator>ovt</dc:creator>
    <dc:date>2006-08-28T08:48:08Z</dc:date>
    <item>
      <title>TCP flow get slower with IPS 4255 5.1(3) in inline mode</title>
      <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541842#M92553</link>
      <description>&lt;P&gt;I have an IPS 4255 with 5.1(3). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logical setup is the following: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                   Internet&lt;/P&gt;&lt;P&gt;                     |&lt;/P&gt;&lt;P&gt;ServerA --- IPS --- PIX --- IPS --- ServerB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The physical setup is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ServerA --- SwitchA --- IPS ---  SwitchB --- PIX --- Internet&lt;/P&gt;&lt;P&gt;ServerB ---/                                    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(ServerA and ServerB are in different DMZs -&amp;gt; in different VLAN-s)&lt;/P&gt;&lt;P&gt;My goal is to protect many segments by one inline IPS, therefore the connection &lt;/P&gt;&lt;P&gt;between SwitchA and SwitchB is an ethernet trunk (for performance reasons this is &lt;/P&gt;&lt;P&gt;an etherchannel trunk (load sharing is src-dst-ip)). &lt;/P&gt;&lt;P&gt;The problem is that ServerA and ServerB have to communicate, and this is done via the PIX.&lt;/P&gt;&lt;P&gt;The communication is very slow and there are many fired TCP Drop and TCP normalization related&lt;/P&gt;&lt;P&gt;signatures. When the IPS is in bypass on mode or one of ther server segment is not watched by the &lt;/P&gt;&lt;P&gt;IPS the communcation speed is ok. I think the speed degradation is because every packet between ServerA and&lt;/P&gt;&lt;P&gt;ServerB travels through the IPS twice. It seems to me that altough they are in seperate VLANs the IPS can not handle &lt;/P&gt;&lt;P&gt;them. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has someone idea how to solve this issue? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541842#M92553</guid>
      <dc:creator>csiszerakos2</dc:creator>
      <dc:date>2019-03-10T10:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: TCP flow get slower with IPS 4255 5.1(3) in inline mode</title>
      <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541843#M92555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had this problem on a few sensors before.  I recommend creating filters for these signatures or disabling them.  We eventually disabled most of them because they were generating massive false positives and were causing too much latency.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Aug 2006 19:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541843#M92555</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2006-08-23T19:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: TCP flow get slower with IPS 4255 5.1(3) in inline mode</title>
      <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541844#M92560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. I have tried to switch off all of the signatures, but it does not help, the latency still exists. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2006 12:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541844#M92560</guid>
      <dc:creator>csiszerakos2</dc:creator>
      <dc:date>2006-08-25T12:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: TCP flow get slower with IPS 4255 5.1(3) in inline mode</title>
      <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541845#M92563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One thing you can do to verify that for sure the sensor's analysis engine is giving you headaches is put the sensor in Bypass Mode.  This essentially turns the sensor into a wire and bypasses all inspection.  If the latency goes away, then you know the problem is the sensor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2006 13:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541845#M92563</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2006-08-25T13:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: TCP flow get slower with IPS 4255 5.1(3) in inline mode</title>
      <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541846#M92565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I put he sensor into bypass mode on, and the latency disappeared. But the IPS worth nothing in bypass mode on. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have contacted the TAC too, it might be a bug or something else... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Aug 2006 15:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541846#M92565</guid>
      <dc:creator>csiszerakos2</dc:creator>
      <dc:date>2006-08-27T15:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: TCP flow get slower with IPS 4255 5.1(3) in inline mode</title>
      <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541847#M92566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is expected.&lt;/P&gt;&lt;P&gt;Disable TCP sequence randomization on the PIX ("norandomseq") for traffic between the vlans. If it doesn't help then add "produce alert" action to the signatures in the Normalizer engine and see which signatures are firing. Then post your results here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Aug 2006 08:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541847#M92566</guid>
      <dc:creator>ovt</dc:creator>
      <dc:date>2006-08-28T08:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: TCP flow get slower with IPS 4255 5.1(3) in inline mode</title>
      <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541848#M92567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi  ..  be aware that the IPS can inspect at 600  Mbps  however, its monitoring interfaces support 1Gbps and hence the sensor could be receiving traffic at faster speed tha it can inspect. this will affect performance on you network. To double check this check the statistics of your interfaces and see whether the ammount of missed packets is dramatically increasing. If that is the case then you need to limit the traffic to be inspected by using filters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps  ...  please rate if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Aug 2006 08:56:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541848#M92567</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-08-28T08:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: TCP flow get slower with IPS 4255 5.1(3) in inline mode</title>
      <link>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541849#M92569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic is about 1-2 megabit/sec through the IPS, so this does not count. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to use the norandomseq but it does not help.(Is it ok that the norandomseq does not appear in the configuration? - I used in this form:  nat (APPL) 0 access-list ACL_NONAT_APPL norandomseq). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I switched off all of the signatures except the normalizers. I switched them just to produce alert and verbose alert no to drop or modify packet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two relevant server are Takson (172.31.5.1) and Keve (172.31.6.1)&lt;/P&gt;&lt;P&gt;The alarms are attached. I see that there is alarm between them :TCP session tracking stopped due to timeout &lt;/P&gt;&lt;P&gt;It seems to me very strange. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akos &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Aug 2006 13:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-flow-get-slower-with-ips-4255-5-1-3-in-inline-mode/m-p/541849#M92569</guid>
      <dc:creator>csiszerakos2</dc:creator>
      <dc:date>2006-08-29T13:37:38Z</dc:date>
    </item>
  </channel>
</rss>

