<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 performance issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-performance-issues/m-p/807847#M970925</link>
    <description>&lt;P&gt;Hi, we have an ASA 5510 with about 140 defined rules in the security policy.&lt;/P&gt;&lt;P&gt;In our company there are some complaints about the performance throughput from one network (inside) to another (dmz).&lt;/P&gt;&lt;P&gt;For example, we have a ecommerce platform that resides in the dmz but uses (at startup of the services only) a database that's on the inside network. When the services of these server applications are started, it takes about 1 hour and 20 minutes to load all data needed. When I connect one of these servers directly on our internal network, the startup only takes about 40 minutes. The amount of data transferred is estimated around 6 GB. The transfer is done by a Oracle client querying an Oracle database.&lt;/P&gt;&lt;P&gt;Is there any reason to believe that the firewall could be a bottleneck here? Too many rules?&lt;/P&gt;&lt;P&gt;Are some rules more cpu-intensive to handle than others?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also have a builtin content security scanning appliance from trendmicro, but I configured the ASA to only inspect http and smtp traffic using this board.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CPU on the firewall shows an average value of around 4% (also during the times the ecommerce applications are loading the data from the database.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 10:59:48 GMT</pubDate>
    <dc:creator>rsnd</dc:creator>
    <dc:date>2019-03-11T10:59:48Z</dc:date>
    <item>
      <title>ASA 5510 performance issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-performance-issues/m-p/807847#M970925</link>
      <description>&lt;P&gt;Hi, we have an ASA 5510 with about 140 defined rules in the security policy.&lt;/P&gt;&lt;P&gt;In our company there are some complaints about the performance throughput from one network (inside) to another (dmz).&lt;/P&gt;&lt;P&gt;For example, we have a ecommerce platform that resides in the dmz but uses (at startup of the services only) a database that's on the inside network. When the services of these server applications are started, it takes about 1 hour and 20 minutes to load all data needed. When I connect one of these servers directly on our internal network, the startup only takes about 40 minutes. The amount of data transferred is estimated around 6 GB. The transfer is done by a Oracle client querying an Oracle database.&lt;/P&gt;&lt;P&gt;Is there any reason to believe that the firewall could be a bottleneck here? Too many rules?&lt;/P&gt;&lt;P&gt;Are some rules more cpu-intensive to handle than others?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also have a builtin content security scanning appliance from trendmicro, but I configured the ASA to only inspect http and smtp traffic using this board.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CPU on the firewall shows an average value of around 4% (also during the times the ecommerce applications are loading the data from the database.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:59:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-performance-issues/m-p/807847#M970925</guid>
      <dc:creator>rsnd</dc:creator>
      <dc:date>2019-03-11T10:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 performance issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-performance-issues/m-p/807848#M970926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont think that ACL's should be a problem, I will probably disable inspection of traffic and apply sniffer to check the packet flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Rohit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2007 12:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-performance-issues/m-p/807848#M970926</guid>
      <dc:creator>rochopra</dc:creator>
      <dc:date>2007-08-20T12:31:13Z</dc:date>
    </item>
  </channel>
</rss>

