cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2335
Views
15
Helpful
8
Replies

Does FPR-2110 have bandwith limitations per SA on IPsec l2l tunnel ?

Loc Nguyen
Level 1
Level 1

Hi,

 

We have two Cisco  FPR-2110 set up site to site vpn.

 

We tested without firewalls, the bandwidth between two sites is 500Mbps.

 

But when we have the Firewall set up site to site vpn, the maximum speed we can have for a TCP Iperf3 test is 150Mbps.

 

Does FPR-2110 have bandwith limitations per SA on IPsec l2l tunnel ?

 

 
There link above talking about it.  What do you think?

 

Thanks

 

Loc

 

 

 

 

1 Accepted Solution

Accepted Solutions

Loc Nguyen
Level 1
Level 1

Update:

After a month troubleshoot with several Cisco TACs. We escalated our case to the highest level of TAC security Team.

 

They confirm it is a bug. Can not do anything to make it better.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp25274

 

Thanks everyone for trying to help.

 

Loc

View solution in original post

8 Replies 8

balaji.bandi
Hall of Fame
Hall of Fame

is this ASA code running on FP ?  then that is correct as per the datasheet.

 

https://www.cisco.com/c/en/us/products/collateral/security/firepower-2100-series/datasheet-c78-742473.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Balaji,

 

I assume you meant FP=FirePower. Yes, the firewall is FP.

 

 I looked into the link you sent, I don't see any information it says the speed limitation of an SA. Could you help to point out?

 

Thanks

Loc

 

 

 since the device support both. but people can run any code on this device, either FTD or ASA, so the original post does not mention you running FTD or ASA, so hence the question asked.

 

ASA 

 

image.png

FTD

 

 

image.png

 

what is your internet or WAN bandwidth capacity? with out FP have you able to get more than 500MB as per your testing ?

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks Balaji again, our FP never get more than 150Mbps. 

 

I am sure that our ISP's ckt speed is stable around 500Mbps. We tested it many times.

 

I think there something on the firewall cause it but I dont know where.

Do you have any IPS other features enabled?

 

is the interface connected have good negotiation? what kind of switches? do you see any errors on switch or output drops?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

No, I don't have IPS.

 

Connection looks good. Full duplex 1000Mbps. No drops, no errors on switches and Firewalls.

and Yes, the firewall is used as FTD. Not ASA.

Loc Nguyen
Level 1
Level 1

Update:

After a month troubleshoot with several Cisco TACs. We escalated our case to the highest level of TAC security Team.

 

They confirm it is a bug. Can not do anything to make it better.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp25274

 

Thanks everyone for trying to help.

 

Loc