cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3589
Views
30
Helpful
13
Replies

Cisco ASA/Firepower throughput per flow

kerstin-534
Level 1
Level 1

Hello,

 

what ist the throughput per throughput on multicore ASA

Cisco ASA ASA5585-SSP-20 1 CPU 8 Core

when using 10Gbit NICs ? Each flow is handled by one core. Is there a limit per core ?

 

thanks

 

 

 

 

1 Accepted Solution

Accepted Solutions

I asked Andrew Ossipov directly at Cisco Live Barcelona today.

 

He told me that on an ASA 5585-X (non-Firepower), the single flow throughput limit is 3-4 Gbps (TCP) or 6-8 Gbps (UDP).

View solution in original post

13 Replies 13

the max throughput for ASA 5585 SSP40 is 20Gbps

BLOCK_DIAGRAM1.PNGBLOCK_DIAGRAM2.PNGBLOCK_DIAGRAM3.PNG

 

Andrew Ossipov did a cisco live have a look BRKSEC-3021

please do not forget to rate.

yes, the Cisco Live with Andrew Ossipov does some clarification, the question is throughput per flow. So the box have a data-sheet throughput of 5 Gbps and 10Gbit NICs. When there is a service, eg a CIFS file service, when doing exact one transfer over the 5585-SSP20 what is the limit on the flow. 

I think the best answer we could get is from cisco tac.

please do not forget to rate.

Are you using the Firepower module? If so, the limiting factor will be that a given flow (5-tuple) is tied to a single Snort process. A Snort process is limited to something like 500 Mbps per instance.

 

https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/200420-Processing-of-Single-Stream-Large-Sessio.html#anc6

No, without Firepower. Simple one TCP connection through ASA in the fastest path.

yes it will be in fastest path if it is in stateful inspection entry.

please do not forget to rate.

I asked Andrew Ossipov directly at Cisco Live Barcelona today.

 

He told me that on an ASA 5585-X (non-Firepower), the single flow throughput limit is 3-4 Gbps (TCP) or 6-8 Gbps (UDP).

nice one Marvin thanks.

please do not forget to rate.

thank you, Marvin

We are opening up a Case with Cisco TAC shortly.  We did some performance testing on single nuttcp flows with the Cisco 5585-X and got limited to 2.9 Gb/s for a single TCP Flow.   Please advise on your reference on (non-Firepower).  We have Model ASA5585-SSP-60 running 9.8(4)40.   The SPEC sheet for the 5585-X is 20 Gbps for NON-VPN multi protocol for total throughput , so its odd that a single flow is limited to 2.9Gbps.

 

Thanks in advance.

 

As I noted in my posting from 30 January 2019, the expected maximum throughput for a single TCP session is 3-4 Gbps. So, if you are getting 2.9 Gbps, I wouldn't expect any more than that. The 20 Gbps number is the expected maximum across multiple sessions/flows, TCP and UDP, from multiple hosts to multiple hosts.

Marvin,

 

Thanks for the response on this.  The Cisco TAC didn't provide any definitive SPECS for the ASA 5585X-SSP-60 hardware yet.  However, we tested our new FPR9K with SM-56 which should be capable of 10 Gbps on single Flow and only got 6 Gbps.  On further review we found that the MSS without it being properly tuned/configured for Jumbo frames is limited to 1380 (1368).  By setting it on the FPR9k via the command: sysopt connection tcpmss 0, it allowed a higher MSS of 8948 to take advantage of our 9K Jumbo Frames MTU. We then got over 9 Gbps on the FPR9K.  Setting the same sysopt command on the 5585-X with SSP-60  it then boosted the single flow performance to 8 Gbps. All tested with the Nuttcp tool.  https://www.nuttcp.net/Welcome%20Page.html and Linux servers with 10Gb NICs.

 

V/R

Marvin,

 

Thanks for the response on this.  The Cisco TAC didn't provide any definitive SPECS for the ASA 5585X-SSP-60 hardware yet.  However, we tested our new FPR9K with SM-56 which should be capable of 10 Gbps on single Flow and only got 6 Gbps.  On further review we found that the MSS without it being properly tuned/configured for Jumbo frames is limited to 1380 (1368).  By setting it on the FPR9k via the command: sysopt connection tcpmss 0, it allowed a higher MSS of 8948 to take advantage of our 9K Jumbo Frames MTU. We then got over 9 Gbps on the FPR9K.  Setting the same sysopt command on the 5585-X with SSP-60  it then boosted the single flow performance to 8 Gbps. All tested with the Nuttcp tool.  https://www.nuttcp.net/Welcome%20Page.html and Linux servers with 10Gb NICs.

 

V/R

 

Review Cisco Networking products for a $25 gift card