06-16-2016 07:22 AM - edited 03-12-2019 12:53 AM
We have an ASA 5555 with 16Gb Ram, 1 CPU, 8 cores. We are on Software Version 9.5(2). We have a 1Gb connection to the Internet. Every time we turn on File Inspection, it crashes our network. We can run a speed test and we are getting upload and download speeds of less than 5Mb on a 1Gb connection. This was a Cisco recommended configuration but it clearly does not work as demonstrated. We haven't gotten any good help from TAC other than to tell us to turn off file inspection. Has anyone else experienced this issue? Do you have any idea of what could fix this problem? We're getting no assistance from Cisco...
06-16-2016 11:18 AM
How are you trying to implement file inspection?
i.e., In a service policy on the base ASA or are you asking about in the ASA FirePOWER service module
06-17-2016 12:17 PM
It's through the FirePower service module which runs on a VM server. However, it maxes out the processors on the ASA and then the network comes to almost a total standstill. We've had a TAC case on it; they say the machine isn't big enough to handle file inspection. The last time we turned it on, it was only inspecting 4 files and it took it down. We're a public library with public computers and have high Internet usage. We really wanted this because people many times click on links that are harmful and they don't know it or they do it intentionally.
06-21-2016 09:41 PM
So you're using a file inspection policy with the AMP license?
What sort of throughout are you typically pushing?
Have you excluded zip files from the file inspection policy?
The 5555-X is a pretty capable box but AMP is the most resource-intensive feature of the FirePOWER module. That said, it should still be usable under any load conditions that are within the design spec.
06-21-2016 10:43 PM
Hello Team,
As Marvin said file inspection will take more intensive resources to work with that feature. But if you already provided the enough resources in the device , it should not be a problem. We can also perform some fine tuning in this. We should have a look at your policy and check if there is anything that overloads the system by consuming all available resources. What are the versions involved here ? Is there any specific reason or bug identified by Cisco TAC due to which they have requested you to turn off the file inspection.
Regards
jetsy
06-22-2016 06:14 AM
I agree that file inspection is intensive but the box was undersized. We have a 1Gb connection to the Internet. Turning off file inspection lets everything else work but when that is part of the reason you bought the product, that isn't an acceptable solution. The 5555 is going to now be replaced with a 4110. Hopefully that will allow us to use the device the way it was demonstrated when it was sold to us.
Anne
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide