cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1924
Views
0
Helpful
2
Replies

ASA AIP SSM-10 Throughput

mmcae
Level 1
Level 1

We have ASA 5520's with AIP SSM-10 IPS mods. When I deployed them, the throughput was somewhat less when the IPS was in

inline mode, but nowhere near 90% less. I was just performing some more test and the throughput is horrific. We have 100 M internet comnnection.

In promiscuous mode I consistently get   Down 90M+ Upload 85-90M+

In inline mode I consistently get   Down 90M +  Upload 9- 11M max . I have tested this numerous times, and it is never any better than this.

Does anyone else experience this since upgraded to the latest engine? We are running 7.04(E4) with the latest sigs.

I have found somehthing about a RegexDepth setting in a post, does anyone know any more about this?

Thanks!!

2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

Here is the enhancement bug for RegexDepth modification (it includes step to modify the RegexDepth setting):

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsv69844

Hope that helps.

Thanks Jennifer. I see this bug is for the IPS 42XX systems. Does it apply also to the AIP SSM. It also shows it should have been fixed in later releases, like 7.01(E3), is this not the case?

I don't seem to have these commands in the AIP SSM.

Failover-ASA-IPS-Sensor# su
                         ^
% Invalid input detected at '^' marker

Failover-ASA-IPS-Sensor#

Thanks again.

Review Cisco Networking for a $25 gift card