06-03-2019 06:58 PM - edited 02-21-2020 09:11 AM
Anyone tried test the Firepower performance ?.
I have a Firepower 2110, i tried to test the FTP download via Firepower. It is very amazing that the max speed only got about 400 Mbps.
Cisco told me that this cause by Snort instance, and one session only get that speed.
I m not happy with Firepower, before that, i was using Juniper devices and i always get 800 - 900 Mbps for download FTP file.
Solved! Go to Solution.
06-03-2019 09:22 PM
You can still block according to traditional 5-tuple (protocol, source and destination address, source and destination port).
As Cisco notes, a single flow that's being inspected by Snort will be limited by the throughput of the instance it is using. That's different than the throughput of the appliance overall.
Expect this to change when Firepower 6.5 comes out with Snort 3 support under the covers. Snort 3 is multi-threaded per instance.
06-03-2019 08:08 PM
You can trust the flow with a prefilter policy and then test the throughput. That will bypass Snort (application-level and other inspections).
06-03-2019 08:46 PM
06-03-2019 09:22 PM
You can still block according to traditional 5-tuple (protocol, source and destination address, source and destination port).
As Cisco notes, a single flow that's being inspected by Snort will be limited by the throughput of the instance it is using. That's different than the throughput of the appliance overall.
Expect this to change when Firepower 6.5 comes out with Snort 3 support under the covers. Snort 3 is multi-threaded per instance.
01-05-2020 07:27 PM
@Marvin Rhoads wrote:You can still block according to traditional 5-tuple (protocol, source and destination address, source and destination port).
As Cisco notes, a single flow that's being inspected by Snort will be limited by the throughput of the instance it is using. That's different than the throughput of the appliance overall.
Expect this to change when Firepower 6.5 comes out with Snort 3 support under the covers. Snort 3 is multi-threaded per instance.
Hi Marvin
I see Cisco release version 6.5 for FP. Can you confirm is it support multi-threaded per instance now ?
01-05-2020 09:22 PM
The introduction of Snort 3 into Firepower was delayed. So it is not yet supported on Firepower 6.5.
Perhaps we will see it in 6.6 which should be out in a couple of months.
05-05-2020 07:51 PM
Hi,
The Firepower 8120 only can upgrade 6.4.8, is there any plan from Cisco the provide version 6.5 for 8000 series?
05-05-2020 09:13 PM
@m.azlan - No. The Firepower 8000 series was end of sales as of June 2019:
6.4.0.8 is currently the latest release. It will continue to get any 6.4.0.x patches and SRU/VDB/Geolocation updates.
It will not get 6.5.x (or later) major releases.
05-06-2020 01:29 AM
Hi Guys
After upgrade to 6.5, my FP 2110 can get speed test around 600Mbps
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide