cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
735
Views
0
Helpful
1
Replies

ASA 5505 - Outside Outbound Bandwidth Issue

Modulus85
Level 1
Level 1

ZyXel DSL modem (10MB download and 768Kbps or so upload)

DSL modem is operating in bridge mode

Cisco ASA 5505 in routed mode with ten users behind the ASA.  Nothing fancy about the ASA setup.

Each user relies on their own FirePass or Cisco VPN client (outbound, no configuration required in the ASA) continously from 8am to 5pm.  Outlook and light application usage over the VPN only.

On Friday, 05/17/13, the outbound connections were working well.  Latency was good throughout the day (less than 40ms to Google).  On the outside interface, output bandwidth was less than 500Kbps (much less for large portions of the day!).  Three users were using streaming Internet radio.

On Monday, 05/20/13, the outbound connections were working poorly.  Latency was bad (170ms and higher to Google).  On the outside interface, output bandwidth was remaining steady throughout the day between 800Kbps and 850Kbps.  Occasionally, the outside output bandwidth would drop to 40Kbps, then 600Kbps and then back to 800Kbps or so.  No user on Monday was uploading any large files, no cloud backup or anything of the sort.  No users were listening to Internet radio.

On Monday afternoon, I shut down five client machines and the outside output bandwidth was still around 800Kbps.

On Monday evening, I stopped by the office after each user had left the building and checked the outside interface output bandwidth and it was between 0Kbps and 45Kbps (virtually no load).  I verified that all machines were powered on, but the VPN clients were disconnected.

On Friday and Monday, for the outside interface, the input bandwidth was  between 200Kbps and 500Kbps with occasional higher spikes when users  downloaded something.

What could cause the difference between Friday and Monday?  Is the DSL upload simply maxed out?  If the DSL upload is maxed out, why did it work well on Friday when I had a greater demand on the connection?

Thank you

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Modulus,

Did you take captures on the outside interface or the ASA ( This to check what is leaving the ASA ) as you are using VPN clients traffic will go encrypted so you will not be able to determine what is the traffic used for but at least you might notice some extra-traffic (outside the VPN traffic) as this does not look right or normal,

Regards

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card