01-04-2017 07:45 AM - edited 03-12-2019 01:44 AM
Hello,
I'm trying to determine as closely as possible the throughput cap on our ASA 5525 with the services we have currently enabled on it.
ANY Connect VPN (40 users at any-given time)
Firepower (1000 users going through the Sourcefire Module)
I found this doc, but I need something more geared towards our environment. Any ideas where I can get this kind of information?
Thanks in advance!
Solved! Go to Solution.
01-04-2017 11:19 AM
The sum of all the crypto, in and out, with a reasonable packet size mix can get to 300Mb/s. So if users mostly pulled 200Mb/s and pushed 100Mb/s, that would take you to your 300Mb/s limit.
Firepower throughput varies depending on weather it is dealing with an attack or not, and the type of traffic flowing through it. You might get 600Mbs to 1Gb/s.
Some flows, like a large file copy, will go reasonably fast. On the other hand, something generating lots of small http requests will use a lot more resources and be slower.
Here is another more up to date table fronm the model comparison tool. I have also added the model below (5516) and the model above (5545).
If you are running into throughput issues sometimes the cheapest approach is to offload all the VPNs onto a dedicated firewall. A 5516 would probably be a good size for you, and not too expensive.
01-04-2017 11:19 AM
The sum of all the crypto, in and out, with a reasonable packet size mix can get to 300Mb/s. So if users mostly pulled 200Mb/s and pushed 100Mb/s, that would take you to your 300Mb/s limit.
Firepower throughput varies depending on weather it is dealing with an attack or not, and the type of traffic flowing through it. You might get 600Mbs to 1Gb/s.
Some flows, like a large file copy, will go reasonably fast. On the other hand, something generating lots of small http requests will use a lot more resources and be slower.
Here is another more up to date table fronm the model comparison tool. I have also added the model below (5516) and the model above (5545).
If you are running into throughput issues sometimes the cheapest approach is to offload all the VPNs onto a dedicated firewall. A 5516 would probably be a good size for you, and not too expensive.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide