11-27-2020 11:11 AM
I have discovered an issue I'm hoping someone can help me with. We are using an asa 5516X as a VPN headend for RA. All the RA traffic goes from the inside interface of the ASA to an FTD 2130. We ran some speed tests and found that when the traffic goes through the ACP of the FTD our speeds are severely limited. if I setup a fastpath rule our VPN speeds are what they should be based on the RA's ISP. IE when I do a speed test from my anyconnect session I get a flat line speed of 6Mbps without the fastpath rule. With the fastpath rule in place I gets speeds of 24Mbps. I've tried changing the ACP rule to "trust" and turning off file and IPS inspection but I get the same results. Only fastpathing the traffic gets me the speed I would expect. All traffic is tunneled to the ASA and so go through the FTD. Running FTD https://6.4.0.9. Any suggestions would be greatly appreciated.
Solved! Go to Solution.
11-28-2020 03:33 AM
A single flow (that is not otherwise fastpathed via a prefilter rule) will always be processed by a single Snort instance. That will limit the throughput of that single flow and not give a true indicator of the overall device performance which is comprised of multiple flows for multiple users and devices.
11-28-2020 03:33 AM
A single flow (that is not otherwise fastpathed via a prefilter rule) will always be processed by a single Snort instance. That will limit the throughput of that single flow and not give a true indicator of the overall device performance which is comprised of multiple flows for multiple users and devices.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide