cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1383
Views
15
Helpful
5
Replies

ASA5506X Performance Capabilities

Hello,

We have an ASA5506X running 9.6.1.

We are currently running a VPN tunnel using: Ikev1 with AES-256, SHA1, and DH 2, and it runs very well.

We are considering changing the config to use: ikev2 with AES-256, SHA256, and DH20.

 

Can anyone tell me if the CPU has enough performance to support this?

 

Your help is appreciated.

1 Accepted Solution

Accepted Solutions

X series is the new model, so you expected to be higher performance.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

5 Replies 5

Hi,
Yes, it should be fine, if you have the same number of VPN tunnels you currently have when using IKEv1....but if you plan on terminating additional tunnels on the 5506, that may have an impact at somepoint.

HTH

balaji.bandi
Hall of Fame
Hall of Fame

I do not see issue here..how many tunnel we are considering here ? 

 

here is the reference :

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/vpn_ike.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

We only have 2 active VPN tunnels running.  Someone told me DH20 is very CPU intensive may cause a slow down on the lower end ASA like the 5506.  Thanks for your help.

X series is the new model, so you expected to be higher performance.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

DH (diffe hellman) is only run a couple of times a day (depending on the lifetime timers) and with only 2 tunnels that's probably not going to cause you an issue. I assume you are not currently experiencing performance issues...so I would imagine you will be fine.

 

This cisco doc, albeit it is discussing IOS IKEv2, I assume this still applies on ASA, recommended DH19 as the preferred DH group when using IKEv2, it's efficient and secure.

 

HTH

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card