cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1969
Views
0
Helpful
8
Replies

Cisco ASA throughput.

milan.glusac
Level 1
Level 1

Hi,

Can someone tell me maxumum throughput on ASA 5516x  if AMP and IPS are on.

We can't get more than 50 Mbit/s on download and 35 Mbit/s on upload.

If i remove AMP and IPS from rule d/u is normal.

 

8 Replies 8

johnlloyd_13
Level 9
Level 9

hi,

see table 2 on this link:

http://www.cisco.com/c/en/us/products/collateral/security/asa-5500-series-next-generation-firewalls/datasheet-c78-733916.html

there's a note which says: Activating more features will change performance  

a 5516-x should be capable of doing 450 Mbps max with avc and ips according to the specs.

In the real world this seems just about 120Mbps for me and Milan is even reporting less..

I think this difference is just too much...

Yes it shoud be at least 120-150 Mbps. 

Here is the rule with AMP only and still it's slow.

Try to add a filter for application: like HTTP or FTP and see if it helps

Alredy tried that . Didn't help either.

Did you try to reload the firewall?

It solves many other issues here...

Marvin Rhoads
Hall of Fame
Hall of Fame

AMP is the most resource-intensive NGIPS feature.

The numbers you are seeing are about what is expected with AVC + IPS + AMP + URL features all active.

Hi,

We also tested ASA 5515 and we got 3x better results with same configuration.

5515 is rated below 5516 so i am confused.

TAC told as that since 5516 have 3 cores throughput is splitted , but i can't find any documentation about that.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card