12-25-2010 09:16 AM - edited 03-10-2019 05:13 AM
We are using an AIM-IPS module in a 1841 and it has been working fine, however we just upgraded our broadband link and didn’t notice a increase in throughput.
We were consistently getting about 16 meg download speeds and this didn’t change with the new service tier. Removing the IPS module (no ids-service module monitoring inline) does give us the new speeds (35+ meg down)
I thought the AIM-IPS module had a limit of 45 meg throughput, before I trouble shoot more, shouldn’t I expect throughput closer to the 45 meg limit?
12-27-2010 02:54 AM
Hi.
several factors can limit throughput:
1- make sure you are on a recent release on the ips module to make sure you have the latest performance tweaks.
2- check cpu inspection load on the ips module:
sh statistics virtual-sensor | inc Load
if it's very high this will limit throughput and you'll need to tweak your current set of signatures to be less busy.
3- make sure the router side is also not having performance issues (check "show proc cpu").
4- are there any features configured on the router side that could be cpu intensive? like zone based firewall, tcp settings etc...
Regards,
Fadi.
12-27-2010 11:55 AM
Ok thanks for the tips - I will do some more investigation.
It is running a zone based firewall, but by just removing the "ids-service module" lines I saw a decent gain in throughput.
That is, zone firewall still configured but with no ids module: we were getting the expected speeds. I was thinking that while the module might add a little latency, since it had its own CPU/Memory it shouldn't cause such a degradation.
I will do some more testing/monitoring - I guess I really wanted to make sure that the ids module was capable of faster performance than I was seeing (i.e. I wasn't troubleshooting a performance problem that wasn't really a problem but was within spec for the device)
12-27-2010 07:03 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide