cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3498
Views
31
Helpful
34
Replies

PIX 515E slow http from inside to dmz network

kvoelker2000
Level 1
Level 1

                  I have a PIX 515E V7.0.4 and I'm having trouble with http access between the inside interface and a DMZ zone I have.  I have a web server setup in the DMZ with an web interface to upload/download files.  I can connect to this interface from a workstation in the inside network but when I try to download a file it is incredibly slow.  If I upload a file there are no speed issues.  If I connect using an https connection then both upload and downloads are at speeds I would expect.

I have disabled http inspect but this didn't improve the speed connection.

Other http communications from inside to outside do not have any speed issues in either direction.

Any thoughts or suggestions appreciated.

Thanks,

Karl

34 Replies 34

Hello,

But you told me you do not see the latency when the traffic comes from outside to the HTTP server on the dmz? Is that correct?

Regards,

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

No,  web traffic from the outside to the server in the DMZ is that same as from the inside net.  Fast upload but slow download.  Other traffic to this server,  SMB, FTP, whether from the outside or inside works fine in both directions.  It appears to just affect http traffic in the DMZ zone.

Karl

Hello,

Got you know!

Okay first of all the PIX will handle all the HTTP connections on the same way. No additional inspection will be add it if the traffic goes to the DMZ. So right now again it looks like something else but first I need to probe you that.

Can you connect at least the DMZ server directly to the ASA DMZ interface and try a quick test?

Regards,

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Same situation as far as getting approval.  The DMZ is our portal for external users and customers.  Taking this down, even only briefly, will take some time for me to schedule.  Are you trying to rule the 3Com switch as the problem?  I am planning on replacing it, with a 3560G, and could probably schedule that in the next couple days.  

Curious where you think the problem may be.

Thanks,

Karl

Hello,

I know but right now I can ensure that the PIX will handle traffic equally unless not configured like that, right now you have a basic setup so nothing is being changed, I saw that over the captures. Traffic are getting lost and not across the PIX.

So that is good, please keep us posted!

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking products for a $25 gift card