05-21-2013 09:41 AM - edited 03-11-2019 06:46 PM
ZyXel DSL modem (10MB download and 768Kbps or so upload)
DSL modem is operating in bridge mode
Cisco ASA 5505 in routed mode with ten users behind the ASA. Nothing fancy about the ASA setup.
Each user relies on their own FirePass or Cisco VPN client (outbound, no configuration required in the ASA) continously from 8am to 5pm. Outlook and light application usage over the VPN only.
On Friday, 05/17/13, the outbound connections were working well. Latency was good throughout the day (less than 40ms to Google). On the outside interface, output bandwidth was less than 500Kbps (much less for large portions of the day!). Three users were using streaming Internet radio.
On Monday, 05/20/13, the outbound connections were working poorly. Latency was bad (170ms and higher to Google). On the outside interface, output bandwidth was remaining steady throughout the day between 800Kbps and 850Kbps. Occasionally, the outside output bandwidth would drop to 40Kbps, then 600Kbps and then back to 800Kbps or so. No user on Monday was uploading any large files, no cloud backup or anything of the sort. No users were listening to Internet radio.
On Monday afternoon, I shut down five client machines and the outside output bandwidth was still around 800Kbps.
On Monday evening, I stopped by the office after each user had left the building and checked the outside interface output bandwidth and it was between 0Kbps and 45Kbps (virtually no load). I verified that all machines were powered on, but the VPN clients were disconnected.
On Friday and Monday, for the outside interface, the input bandwidth was between 200Kbps and 500Kbps with occasional higher spikes when users downloaded something.
What could cause the difference between Friday and Monday? Is the DSL upload simply maxed out? If the DSL upload is maxed out, why did it work well on Friday when I had a greater demand on the connection?
Thank you
05-21-2013 04:27 PM
Hello Modulus,
Did you take captures on the outside interface or the ASA ( This to check what is leaving the ASA ) as you are using VPN clients traffic will go encrypted so you will not be able to determine what is the traffic used for but at least you might notice some extra-traffic (outside the VPN traffic) as this does not look right or normal,
Regards
Julio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide