04-27-2011 07:54 AM - edited 03-11-2019 01:26 PM
To sum it up the ASA is maxing out at 7MB down on a 25MB connection. The connection was tested with the ASA removed and the connection is fine.
This popped out at me the most but i'm not sure what it means:
12884935775 switch ingress policy drops for eth 0/0
ciscoasa# show interface
Interface Vlan1 "inside", is up, line protocol is up
Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec
MAC address 0025.84ba.a5bf, MTU 1500
IP address 192.192.192.1, subnet mask 255.255.255.0
Traffic Statistics for "inside":
60970690 packets input, 13913244351 bytes
58976961 packets output, 51852996074 bytes
11661619 packets dropped
1 minute input rate 73 pkts/sec, 17085 bytes/sec
1 minute output rate 77 pkts/sec, 58339 bytes/sec
1 minute drop rate, 4 pkts/sec
5 minute input rate 184 pkts/sec, 71247 bytes/sec
5 minute output rate 140 pkts/sec, 100504 bytes/sec
5 minute drop rate, 4 pkts/sec
Interface Vlan2 "outside", is up, line protocol is up
Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec
MAC address 0025.84ba.a5bf, MTU 1500
IP address 64.132.143.181, subnet mask 255.255.255.240
Traffic Statistics for "outside":
59393878 packets input, 55428940778 bytes
49439745 packets output, 11588292732 bytes
671362 packets dropped
1 minute input rate 70 pkts/sec, 57386 bytes/sec
1 minute output rate 62 pkts/sec, 15718 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 131 pkts/sec, 99810 bytes/sec
5 minute output rate 174 pkts/sec, 70422 bytes/sec
5 minute drop rate, 0 pkts/sec
Interface Vlan12 "Guest1", is up, line protocol is up
Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec
MAC address 0025.84ba.a5bf, MTU 1500
IP address 10.0.0.254, subnet mask 255.255.255.0
Traffic Statistics for "Guest1":
25319316 packets input, 3816960570 bytes
3983553 packets output, 3862554401 bytes
20598136 packets dropped
1 minute input rate 6 pkts/sec, 698 bytes/sec
1 minute output rate 0 pkts/sec, 136 bytes/sec
1 minute drop rate, 4 pkts/sec
5 minute input rate 6 pkts/sec, 674 bytes/sec
5 minute output rate 0 pkts/sec, 101 bytes/sec
5 minute drop rate, 4 pkts/sec
Interface Ethernet0/0 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Full-Duplex(Full-duplex), 100 Mbps(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5b7, MTU not set
IP address unassigned
59625610 packets input, 56589417802 bytes, 0 no buffer
Received 121934 broadcasts, 0 runts, 0 giants
205101 input errors, 205101 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
12884935775 switch ingress policy drops
49439776 packets output, 12647462703 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/1 "", is down, line protocol is down
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex, Auto-Speed
Available but not configured via nameif
MAC address 0025.84ba.a5b8, MTU not set
IP address unassigned
27929 packets input, 2231730 bytes, 0 no buffer
Received 1401 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
1215 switch ingress policy drops
4146822 packets output, 691162685 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/2 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5b9, MTU not set
IP address unassigned
108154469 packets input, 20904268305 bytes, 0 no buffer
Received 17076444 broadcasts, 0 runts, 0 giants
150631 input errors, 1 CRC, 0 frame, 150629 overrun, 0 ignored, 0 abort
0 L2 decode drops
12884961778 switch ingress policy drops
99512019 packets output, 57258966359 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/3 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5ba, MTU not set
IP address unassigned
53107701 packets input, 7048981307 bytes, 0 no buffer
Received 25152462 broadcasts, 0 runts, 0 giants
75668 input errors, 0 CRC, 0 frame, 75667 overrun, 0 ignored, 0 abort
0 L2 decode drops
17179903698 switch ingress policy drops
44326368 packets output, 4312679805 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/5 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5bc, MTU not set
IP address unassigned
192436 packets input, 20479294 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
8589967618 switch ingress policy drops
39213895 packets output, 6080350462 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/6 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5bd, MTU not set
IP address unassigned
3121302 packets input, 498409602 bytes, 0 no buffer
Received 235583 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
8589969007 switch ingress policy drops
42570272 packets output, 9835351746 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
04-27-2011 01:46 PM
Hi Jason,
Is Ethernet0/0 the port that connects to the Internet? If so, there are a large number of CRC errors on that interface:
205101 input errors, 205101 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
This is usually caused by a speed/duplex mismatch. The settings should match whatever is set on the device the ASA connects to. Try changing the speed and duplex to auto and then do 'clear interface' to reset the error counters:
interface e0/0
speed auto
duplex auto
clear interface
Hope that helps.
-Mike
04-27-2011 01:51 PM
Thanks for pointing that out. I forgot to mention at one point for troublshooting I tried to chage the interface speed and I belive that is where the CRC errors are coming from. I cleared the stats and since then no more CRC errors are being viewed. The issue is still there but the CRC were caused by earlier troublshooting.
04-27-2011 02:26 PM
Hello,
Would you please paste your running configuration? I want to know if you have any of the following things:
HTTP filter options
HTTP inspection
QoS configured
SSC card involved
Also, are you connected directly to the ASA? Can you try to download a file directly connected to the Internet router and then do the same when connected behind the ASA firewall?
If you are able to do that test, please start wireshark when doing the download, then when connected behind the firewall, please start a packet capture when doing the same download on the inside and outside interface of the firewall, so we can analyze the Input/Output rates.
Cheers
Mike
04-28-2011 07:11 AM
I only have remote access to the ASA currently but I will get all the information I can till I can get physical access. Connected directly to the ISP modem the speed is 20Mb down connected directly the ASA the speed is aorund 7MB down.
Below is the new show interface that had the stats cleared last night and let run till this morning.
Interface Vlan1 "inside", is up, line protocol is up
Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec
MAC address 0025.84ba.a5bf, MTU 1500
IP address 192.192.192.1, subnet mask 255.255.255.0
Traffic Statistics for "inside":
1699136 packets input, 365889334 bytes
1582846 packets output, 1330972492 bytes
255633 packets dropped
1 minute input rate 192 pkts/sec, 18512 bytes/sec
1 minute output rate 255 pkts/sec, 309449 bytes/sec
1 minute drop rate, 4 pkts/sec
5 minute input rate 44 pkts/sec, 8631 bytes/sec
5 minute output rate 41 pkts/sec, 25659 bytes/sec
5 minute drop rate, 4 pkts/sec
Interface Vlan2 "outside", is up, line protocol is up
Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec
MAC address 0025.84ba.a5bf, MTU 1500
IP address 64.132.143.181, subnet mask 255.255.255.240
Traffic Statistics for "outside":
1705308 packets input, 1348744583 bytes
1671154 packets output, 745037104 bytes
20975 packets dropped
1 minute input rate 252 pkts/sec, 310646 bytes/sec
1 minute output rate 206 pkts/sec, 19326 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 37 pkts/sec, 25546 bytes/sec
5 minute output rate 36 pkts/sec, 8173 bytes/sec
5 minute drop rate, 0 pkts/sec
Interface Vlan12 "Guest1", is up, line protocol is up
Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec
MAC address 0025.84ba.a5bf, MTU 1500
IP address 10.0.0.254, subnet mask 255.255.255.0
Traffic Statistics for "Guest1":
640441 packets input, 451206607 bytes
235123 packets output, 22489484 bytes
255533 packets dropped
1 minute input rate 5 pkts/sec, 569 bytes/sec
1 minute output rate 0 pkts/sec, 36 bytes/sec
1 minute drop rate, 4 pkts/sec
5 minute input rate 5 pkts/sec, 630 bytes/sec
5 minute output rate 0 pkts/sec, 137 bytes/sec
5 minute drop rate, 4 pkts/sec
Interface Ethernet0/0 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Full-Duplex(Full-duplex), 100 Mbps(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5b7, MTU not set
IP address unassigned
1715924 packets input, 1387217073 bytes, 0 no buffer
Received 3079 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
6170 switch ingress policy drops
1674502 packets output, 780669552 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/1 "", is down, line protocol is down
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex, Auto-Speed
Available but not configured via nameif
MAC address 0025.84ba.a5b8, MTU not set
IP address unassigned
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
0 switch ingress policy drops
0 packets output, 0 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/2 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5b9, MTU not set
IP address unassigned
1799538 packets input, 413345564 bytes, 0 no buffer
Received 320388 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
446 switch ingress policy drops
1586035 packets output, 1364705821 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/3 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5ba, MTU not set
IP address unassigned
399454 packets input, 50953863 bytes, 0 no buffer
Received 300177 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
1247 switch ingress policy drops
32731 packets output, 3812121 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/4 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5bb, MTU not set
IP address unassigned
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
0 switch ingress policy drops
419587 packets output, 53105944 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/5 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5bc, MTU not set
IP address unassigned
7231 packets input, 770618 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
6199 switch ingress policy drops
420466 packets output, 52963068 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/6 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5bd, MTU not set
IP address unassigned
346535 packets input, 425288639 bytes, 0 no buffer
Received 17359 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
6202 switch ingress policy drops
630532 packets output, 78303975 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
Interface Ethernet0/7 "", is up, line protocol is up
Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
Available but not configured via nameif
MAC address 0025.84ba.a5be, MTU not set
IP address unassigned
5578 packets input, 425978 bytes, 0 no buffer
Received 2457 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 L2 decode drops
0 switch ingress policy drops
420710 packets output, 53253787 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
0 rate limit drops
0 switch egress policy drops
04-28-2011 09:11 AM
Hello,
Ok, let me know when you have time to do the things physically, meantime, is there a possibility to add a filter URL except for a host and then that you try to do the test again from the host you did the except?
Mike
05-02-2011 05:17 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide