cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
956
Views
0
Helpful
6
Replies

Firesight IPS Bandwidth and Best Practice

ccg-security
Level 1
Level 1

Hi Cisco Support,

We would like to ask you some important details that we need regarding IPS. These topics are "Bandwidth", "Effort", and "Best Practice". So First, regarding the bandwidth, we would like to know if there are any impact on our bandwidth if all traffic will pass through IPS knowing that IPS will monitor all those traffic. Second, how much effort we will need to implement these kind of setup. Lastly, what is/are the best practices on implementing IPS in an organization.

Thank you and best regards!

6 Replies 6

Philip D'Ath
VIP Alumni
VIP Alumni

Short lived flows cause the most impact.  Big long file transfer have only a small impact.  Certain types of traffic need a lot more CPU, like http.  If you use ssl decryption then that uses a tonne of CPU.

Firepower is quite time intensive to setup.  I would allow a full day. Most of that time is spent upgrading it to current software and deploying the Firepower virtual management centre.

How much bandwidth are you looking to protect?

Hi Philip,

Thank you for the reply. We are only using Protection license so we are using most of IPS signatures. Do you have any documentation stated that there's an impact on the bandwith during inspection?

Thank you and best regards!

I don't have such a document - but it is common sense. The device has to use CPU to look at traffic.  The more signatures and the more traffic it uses the more CPU will be required.

if I am not wrong turning on FireAMP for malware analysis adds a significant impact to performance. 

That's correct - the AMP feature is the most CPU-intensive of the lot.

The performance hit varies by platform. It will be a lot less on the new FirePOWER 2100 series due to how they use dedicated Network Processing Unit (NPU) ASICs for some of the NGIPS features vs a single multi-core CPU like on the 5500-X appliances.

Your partner can request (via Partner Help Desk) Cisco run your traffic and bandwidth and feature profile through an internal-only performance estimator tool.

That tool will give you a report of exactly how much capacity the various platforms will use in your scenario,

Review Cisco Networking for a $25 gift card