03-24-2021 03:30 PM
Hi,
We have two Cisco FPR-2110 set up site to site vpn.
We tested without firewalls, the bandwidth between two sites is 500Mbps.
But when we have the Firewall set up site to site vpn, the maximum speed we can have for a TCP Iperf3 test is 150Mbps.
Does FPR-2110 have bandwith limitations per SA on IPsec l2l tunnel ?
Thanks
Loc
Solved! Go to Solution.
04-08-2021 09:14 AM
Update:
After a month troubleshoot with several Cisco TACs. We escalated our case to the highest level of TAC security Team.
They confirm it is a bug. Can not do anything to make it better.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp25274
Thanks everyone for trying to help.
Loc
03-24-2021 03:57 PM
is this ASA code running on FP ? then that is correct as per the datasheet.
03-24-2021 04:50 PM
Balaji,
I assume you meant FP=FirePower. Yes, the firewall is FP.
I looked into the link you sent, I don't see any information it says the speed limitation of an SA. Could you help to point out?
Thanks
Loc
03-24-2021 05:02 PM - edited 03-24-2021 05:03 PM
since the device support both. but people can run any code on this device, either FTD or ASA, so the original post does not mention you running FTD or ASA, so hence the question asked.
ASA
FTD
what is your internet or WAN bandwidth capacity? with out FP have you able to get more than 500MB as per your testing ?
03-24-2021 05:43 PM
Thanks Balaji again, our FP never get more than 150Mbps.
I am sure that our ISP's ckt speed is stable around 500Mbps. We tested it many times.
I think there something on the firewall cause it but I dont know where.
03-24-2021 05:53 PM - edited 03-24-2021 05:54 PM
Do you have any IPS other features enabled?
is the interface connected have good negotiation? what kind of switches? do you see any errors on switch or output drops?
03-24-2021 06:31 PM
No, I don't have IPS.
Connection looks good. Full duplex 1000Mbps. No drops, no errors on switches and Firewalls.
03-24-2021 05:44 PM
and Yes, the firewall is used as FTD. Not ASA.
04-08-2021 09:14 AM
Update:
After a month troubleshoot with several Cisco TACs. We escalated our case to the highest level of TAC security Team.
They confirm it is a bug. Can not do anything to make it better.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp25274
Thanks everyone for trying to help.
Loc
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide