cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1697
Views
0
Helpful
4
Replies

FTD 6.2.0.1 Slow Connection

I have a 5516-X with On-box mgmt with around 1k users behind him and internet connection 150Mbps.
When everyone comes and connects on the internet, the internet stay completely slow and the FTD stopped responding in the management interface.. We are just using the URL Filtering, no IPs, Geo.

I checked the interfaces no CRC or input errors, i checked the traffic and don´t find Nothing.

My question is: The On-box mgmt can be compromised the traffic?

1 Accepted Solution

Accepted Solutions

Dennis Perto
Level 5
Level 5

Hi maiquelconsalter  

By using on-box management you are using CPU cycles on running the management software it self, while the 5516-X really could use all the processing power possible to inspect your traffic. 

URL filtering is hitting the Atom processor harder than AMP would do which is quite opposite of what we are seing on all the other ASAs with Xeon-family processors. 

You can expect to see around 140Mbits of throughput on an 5516-X running AVC+IPS+URL filtering. (With a Firepower Management Center doing next to it)

View solution in original post

4 Replies 4

Dennis Perto
Level 5
Level 5

Hi maiquelconsalter  

By using on-box management you are using CPU cycles on running the management software it self, while the 5516-X really could use all the processing power possible to inspect your traffic. 

URL filtering is hitting the Atom processor harder than AMP would do which is quite opposite of what we are seing on all the other ASAs with Xeon-family processors. 

You can expect to see around 140Mbits of throughput on an 5516-X running AVC+IPS+URL filtering. (With a Firepower Management Center doing next to it)

Hi @dennisperto thanks for your answer. 

I thought the throuput with AVC + URL + IPS was 450MB, but 450MB is just AVC + IPS http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-733916.html

Thanks.



You can expect 200Mbit with AVC + IPS. :)

Review Cisco Networking products for a $25 gift card