Hey all,
I've recently been seeing some issues on an 877W running c870-advipservicesk9-mz.124-24.T4.bin. With certain sites (YouTube for example) we see transfer rates ramping up to around 6.5Mbps, which is close to the sync rate of the ADSL connection. However, once at that peak, they start to drop off again and never recover - dropping to around a few bytes/sec.
Originally I suspected this would relate to windowing and/or PMTUD and so disabled the ZBFW. Having done this, sites that were previously unusable were now working fine with acceptable download rates. Reinstating ZBFW restores the prior behaviour. Packet captures made on the host running the download and also on the router via RITE don't show up anything different between the 2 scenarios.
The ZBFW config is very straightforward - ZPs for IN-OUT, OUT-IN. OUT-IN and OUT-VPN/IN-VPN, with a whole bunch of protocols being inspected outbound (incl http, tcp, icmp), and everything else OUT being passed. Inbound, IPSEC protocols are matched and everything else is dropped.
Has anyone seen anything like this before?
Many thanks,
Jon.