cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1147
Views
5
Helpful
2
Replies

Questionable FTD Egress Latency

Multiple users have recently reported connection slowness to an APP VM that they have access to through an FTD HA Pair in our Colo DC. After running a trace from their access switch to the server that sites behind the firewall, I noticed that while going through the egress interface of the FTD alone is around 75ms on average. We do not do any heavy L7 packet inspection, just L3/L4 Security Rules, so I am a bit confused about the reason for the high latency. Is this latency time normal to see on an FTD? Is there any possible way to work to bring this time down? Thanks.

 

1 172.30.254.70 2 msec
172.30.254.68 2 msec
172.30.254.70 2 msec
2 172.30.254.0 2 msec
172.30.254.2 3 msec
172.30.254.0 1 msec
3 172.30.211.253 2 msec 3 msec 1 msec
4 172.30.77.10 1 msec 2 msec 1 msec
5 10.62.250.153 4 msec 4 msec 4 msec
6 10.251.5.106 [MPLS: Label 24369 Exp 0] 5 msec 5 msec 5 msec
7 10.251.15.113 4 msec 4 msec 4 msec
8 10.93.16.1 76 msec 75 msec 78 msec    FTD EGRESS INTERFACE (NEXT HOP SERVER)

 

 

UPDATE: I have noticed that within FMC, the CPU0 is currently sitting around 85-90%. Could this be a legit reason for the high latency? If so, could a possible reboot solve this? Thanks.

2 Replies 2

Sheraz.Salim
VIP Alumni
VIP Alumni

even though you not using the L7 inspection on FTD but by default if no rules are configured the default policy kicks in. what you can do is create a L7 ACP rule and put the server and user in "Trust". by doing this FTD will not do a default policy check.

Here 

trust.PNG

please do not forget to rate.

Hi,

So to confirm, hops 7 and 8 are directly connected using ethernet cable
(i.e no L2 network between them or ISP is not hiding IPs).? This is
important to confirm cuz you might be having another network in between or
a microware link for example which can add latency.

Next, if FTD CPU is high, it can cause slowness and its important to know
why a single CPU is at high usage continuously (you might be having an
elephant flow which is constantly inspected by FTD such as backup).

Here is a good resource for troubleshooting.

https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-3121.pdf

**** please remember to rate useful posts
Review Cisco Networking for a $25 gift card