cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1127
Views
0
Helpful
4
Replies

877 ADSL2 speed problem

garvey6969
Level 1
Level 1

Hi All:

I'm a cisco newb, have many years experience with FreeBSD and OpenBSD administration.  I just purchased an 877 ADSL router.  After a lot of trial and error, and head-banging, I was able to configure the router through SDM, and connect it to the internet.  I still have one major problem, there is something wrong with the speed.  I have a 15Mbs DS/800k US ADSL2+ connection.  The line works well and I am able to achieve full 15Mb downloads with my current DSL modem/router.  However, when I connect with the 877 I can only download around 100-200k.  I guess there is a setting that is misconfigured but I don't know where.  I would really appreciate some help from the pros here.  Below is some info to help debug the problem, if there is something else I need to post please let me know.

----------------------------------------------------------------------------------------------------------------

yourname#show interfaces
ATM0 is up, line protocol is up
  Hardware is MPC ATMSAR (with Alcatel ADSL Module)
  MTU 4470 bytes, sub MTU 4470, BW 930 Kbit/sec, DLY 390 usec,
     reliability 255/255, txload 1/255, rxload 23/255
  Encapsulation ATM, loopback not set
  Encapsulation(s): AAL5  AAL2, PVC mode
  10 maximum active VCs, 1024 VCs per VP, 1 current VCCs
  VC Auto Creation Disabled.
  VC idle disconnect time: 300 seconds
  Last input 00:06:09, output 00:00:09, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/75/89/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: Per VC Queueing
  5 minute input rate 84000 bits/sec, 0 packets/sec
  5 minute output rate 0 bits/sec, 0 packets/sec
     3586 packets input, 4401146 bytes, 0 no buffer
     Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
     2310 packets output, 265426 bytes, 0 underruns
     0 output errors, 0 collisions, 1 interface resets
     0 unknown protocol drops
     0 output buffer failures, 0 output buffers swapped out
ATM0.1 is up, line protocol is up
  Hardware is MPC ATMSAR (with Alcatel ADSL Module)
  MTU 4470 bytes, BW 930 Kbit/sec, DLY 390 usec,
     reliability 255/255, txload 1/255, rxload 23/255
  Encapsulation ATM
     3675 packets input, 4421483 bytes
     2310 packets output, 265426 bytes
     0 OAM cells input, 0 OAM cells output
  AAL5 CRC errors : 0
  AAL5 SAR Timeouts : 0
  AAL5 Oversized SDUs : 0
  Last clearing of "show interface" counters never
Dialer0 is up, line protocol is up (spoofing)
  Hardware is Unknown
reliability 255/255, txload 1/255, rxload 103/255
  Encapsulation PPP, loopback not set
  Keepalive set (10 sec)
  DTR is pulsed for 1 seconds on reset
  Interface is bound to Vi1
  Last input never, output never, output hang never
  Last clearing of "show interface" counters 00:07:45
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: weighted fair
  Output queue: 0/1000/64/0 (size/max total/threshold/drops)
     Conversations  0/0/16 (active/max active/max total)
     Reserved Conversations 0/0 (allocated/max allocated)
     Available Bandwidth 42 kilobits/sec
  5 minute input rate 59000 bits/sec, 0 packets/sec
  5 minute output rate 0 bits/sec, 0 packets/sec
     3561 packets input, 4281548 bytes
     2321 packets output, 192950 bytes
Bound to:
Virtual-Access1 is up, line protocol is up
  Hardware is Virtual Access interface
  MTU 1500 bytes, BW 930 Kbit/sec, DLY 20000 usec,
     reliability 255/255, txload 1/255, rxload 16/255
  Encapsulation PPP, LCP Open
  Open: IPCP
  PPPoE vaccess, cloned from Dialer0
  Vaccess status 0x44, loopback not set
  Keepalive set (10 sec)
  DTR is pulsed for 5 seconds on reset
  Interface is bound to Di0 (Encapsulation PPP)
  Last input 00:01:11, output never, output hang never
  Last clearing of "show interface" counters 00:06:59
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 61000 bits/sec, 0 packets/sec
  5 minute output rate 0 bits/sec, 0 packets/sec
     3604 packets input, 4281220 bytes, 0 no buffer
     Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
2333 packets output, 193103 bytes, 0 underruns
     0 output errors, 0 collisions, 0 interface resets
     0 unknown protocol drops
     0 output buffer failures, 0 output buffers swapped out
     0 carrier transitions
FastEthernet0 is up, line protocol is up
  Hardware is Fast Ethernet, address is e804.622c.5494 (bia e804.622c.5494)
  MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive set (10 sec)
  Full-duplex, 100Mb/s
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input never, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 2000 bits/sec, 1 packets/sec
  5 minute output rate 52000 bits/sec, 2 packets/sec
     4155 packets input, 470340 bytes, 0 no buffer
     Received 10 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 input packets with dribble condition detected
     4776 packets output, 4299826 bytes, 0 underruns
     0 output errors, 0 collisions, 2 interface resets
     0 unknown protocol drops
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier
     0 output buffer failures, 0 output buffers swapped out
FastEthernet1 is up, line protocol is down
  Hardware is Fast Ethernet, address is e804.622c.5495 (bia e804.622c.5495)
  MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive set (10 sec)
  Auto-duplex, Auto-speed
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input never, output never, output hang never
Last clearing of "show interface" counters never
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 0 bits/sec, 0 packets/sec
  5 minute output rate 0 bits/sec, 0 packets/sec
     0 packets input, 0 bytes, 0 no buffer
     Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 input packets with dribble condition detected
     0 packets output, 0 bytes, 0 underruns
     0 output errors, 0 collisions, 2 interface resets
     0 unknown protocol drops
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier
     0 output buffer failures, 0 output buffers swapped out
FastEthernet2 is up, line protocol is down
  Hardware is Fast Ethernet, address is e804.622c.5496 (bia e804.622c.5496)
  MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive set (10 sec)
  Auto-duplex, Auto-speed
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input never, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 0 bits/sec, 0 packets/sec
  5 minute output rate 0 bits/sec, 0 packets/sec
     0 packets input, 0 bytes, 0 no buffer
     Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 input packets with dribble condition detected
     0 packets output, 0 bytes, 0 underruns
     0 output errors, 0 collisions, 2 interface resets
     0 unknown protocol drops
     0 babbles, 0 late collision, 0 deferred
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
     0 packets output, 0 bytes, 0 underruns
     0 output errors, 0 collisions, 0 interface resets
     0 unknown protocol drops
     0 output buffer failures, 0 output buffers swapped out
Virtual-Access1 is up, line protocol is up
  Hardware is Virtual Access interface
  MTU 1500 bytes, BW 930 Kbit/sec, DLY 20000 usec,
     reliability 255/255, txload 1/255, rxload 12/255
  Encapsulation PPP, LCP Open
  Open: IPCP
  PPPoE vaccess, cloned from Dialer0
  Vaccess status 0x44, loopback not set
  Keepalive set (10 sec)
  DTR is pulsed for 5 seconds on reset
  Interface is bound to Di0 (Encapsulation PPP)
  Last input 00:02:30, output never, output hang never
  Last clearing of "show interface" counters 00:08:18
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 44000 bits/sec, 0 packets/sec
  5 minute output rate 0 bits/sec, 0 packets/sec
     3625 packets input, 4283681 bytes, 0 no buffer
     Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
     2357 packets output, 199946 bytes, 0 underruns
     0 output errors, 0 collisions, 0 interface resets
     0 unknown protocol drops
     0 output buffer failures, 0 output buffers swapped out
     0 carrier transitions
Vlan1 is up, line protocol is up
  Hardware is EtherSVI, address is
  Description: $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$
  Internet address is x.x.10.1/29
  MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
DTR is pulsed for 5 seconds on reset
  Interface is bound to Di0 (Encapsulation PPP)
  Last input 00:02:30, output never, output hang never
  Last clearing of "show interface" counters 00:08:18
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 44000 bits/sec, 0 packets/sec
  5 minute output rate 0 bits/sec, 0 packets/sec
     3625 packets input, 4283681 bytes, 0 no buffer
     Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
     2357 packets output, 199946 bytes, 0 underruns
     0 output errors, 0 collisions, 0 interface resets
     0 unknown protocol drops
     0 output buffer failures, 0 output buffers swapped out
     0 carrier transitions
Vlan1 is up, line protocol is up
  Hardware is EtherSVI, address is e804.622c.5494 (bia e804.622c.5494)
  Description: $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$
  Internet address is x.x.10.1/29
  MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input 00:00:00, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 1000 bits/sec, 1 packets/sec
  5 minute output rate 37000 bits/sec, 1 packets/sec
     4255 packets input, 466242 bytes, 0 no buffer
     Received 5 broadcasts, 0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     4376 packets output, 4289012 bytes, 0 underruns
     0 output errors, 1 interface resets
     0 unknown protocol drops
     0 output buffer failures, 0 output buffers swapped out

yourname#sh ver
Cisco IOS Software, C870 Software (C870-ADVSECURITYK9-M), Version 12.4(24)T4, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Fri 03-Sep-10 17:16 by prod_rel_team

ROM: System Bootstrap, Version 12.3(8r)YI4, RELEASE SOFTWARE

yourname uptime is 19 minutes
System returned to ROM by power-on
System image file is "flash:c870-advsecurityk9-mz.124-24.t4.bin"


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

Cisco 877 (MPC8272) processor (revision 0x400) with 118784K/12288K bytes of memory.
Processor board ID
MPC8272 CPU Rev: Part Number 0xC, Mask Number 0x10
4 FastEthernet interfaces
1 ATM interface
128K bytes of non-volatile configuration memory.
24576K bytes of processor board System flash (Intel Strataflash)

Configuration register is 0x2102

yourname#show dsl interface
ATM0
Alcatel 20190 chipset information
         ATU-R (DS)            ATU-C (US)
Modem Status:     Showtime (DMTDSL_SHOWTIME)
DSL Mode:     ITU G.992.5 (ADSL2+) Annex A
ITU STD NUM:      0x03                 0x2
Chip Vendor ID:     'STMI'                 'IFTN'
Chip Vendor Specific:  0x0000             0x8273
Chip Vendor Country:   0x0F             0xB5
Modem Vendor ID: 'CSCO'                 '    '
Modem Vendor Specific: 0x0000             0x0000
Modem Vendor Country:  0xB5             0x00
Serial Number Near:    FCZ1443C2TE
Serial Number Far:    
Modem VerChip ID:      C196P (1)
DFE BOM:     DFE3.0 Annex A (1)
Capacity Used:     82%                 100%
Noise Margin:     14.0 dB             12.5 dB
Output Power:     14.0 dBm             12.5 dBm
Attenuation:      7.0 dB              4.0 dB
FEC ES Errors:      0                  0
ES Errors:      1                  0
SES Errors:      1                  0
LOSES Errors:      1                  0
UES Errors:      0                 23
Defect Status:     None                            None                       
Last Fail Code:     None
Watchdog Counter: 0xEC
Watchdog Resets: 0
Selftest Result: 0x00
Subfunction:     0x00
Interrupts:     8256 (0 spurious)
PHY Access Err:     0
Activations:     1
LED Status:     ON
LED On Time:     100
LED Off Time:     100
Init FW:     init_AMR-3.0.014_no_bist.bin
Operation FW:     AMR-3.0.014.bin
FW Source:     embedded
FW Version:     3.0.14
       
          DS Channel1      DS Channel0    US Channel1      US Channel0
Speed (kbps):              0           18752             0             930
Cells:                  0           95522             0         1597792
Reed-Solomon EC:          0               0             0               0
CRC Errors:              0               0             0               0
Header Errors:              0               0             0               0
Total BER:          0E-0         0E-0
Leakage Average BER:      0E-0         0E-0
Interleave Delay:         0              16             0              60
            ATU-R (DS)    ATU-C (US)
Bitswap:           enabled          enabled
Bitswap success:          0                  0
Bitswap failure:          0                  0

LOM Monitoring : Disabled


DMT Bits Per Bin
000: 0 0 0 0 0 0 2 3 5 6 7 8 9 9 A B
010: B B C C C C C C C C C C C C B B
020: 0 8 9 9 A B C C C C C D D D D D
030: D D E E E E E E E E E E E E E E
040: E E E E E E E E E E E E E E E E
050: E E E E E E E E E E E E E E E E
060: E E D D D 2 D D D D D D D D D D
070: D D C C D C C C C C C C C B C C
080: C C C C C C C C C D D D D D D D
090: D D D D D D D D D D D D D C C C
0A0: C C C C C C C C C C C C C C B B
0B0: B B B B B B B B B B B B B B B B
0C0: C C C C C C C C C C C C C C C C
0D0: C C C C C C C C C C C C C C C C
0E0: C C C C C C C C C C C C C C C C
0F0: C C C C C C C C C C C C C C C C
100: C C C C C C C C C C C C C C C C
110: C C C C C C C C C C C C C C C C
120: C C C C C C C C C C C C C C C C
130: C C C C C C C C C C C C C C C C
LOM Monitoring : Disabled


DMT Bits Per Bin
000: 0 0 0 0 0 0 2 3 5 6 7 8 9 9 A B
010: B B C C C C C C C C C C C C B B
020: 0 8 9 9 A B C C C C C D D D D D
030: D D E E E E E E E E E E E E E E
040: E E E E E E E E E E E E E E E E
050: E E E E E E E E E E E E E E E E
060: E E D D D 2 D D D D D D D D D D
070: D D C C D C C C C C C C C B C C
080: C C C C C C C C C D D D D D D D
090: D D D D D D D D D D D D D C C C
0A0: C C C C C C C C C C C C C C B B
0B0: B B B B B B B B B B B B B B B B
0C0: C C C C C C C C C C C C C C C C
0D0: C C C C C C C C C C C C C C C C
0E0: C C C C C C C C C C C C C C C C
0F0: C C C C C C C C C C C C C C C C
100: C C C C C C C C C C C C C C C C
110: C C C C C C C C C C C C C C C C
120: C C C C C C C C C C C C C C C C
130: C C C C C C C C C C C C C C C C
140: C C C C C C C C C C C C C C C C
150: C C C C C C C C C C C C C C C B
160: B B B B B B B B B B B B B B B B
170: B B B B B B A A A A A A A A A A
180: A A A A A A A A A A A A A A A A
190: A A A A 9 9 9 9 A 9 9 9 9 9 9 9
1A0: 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9
1B0: A A A 9 9 A A 9 9 A 9 A 9 A A A
1C0: 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9
1D0: 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9
1E0: 9 9 9 9 9 9 9 9 9 9 9 8 8 8 8 8
1F0: 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8

DSL: Training log buffer capability is not enabled

yourname# show running-config
Building configuration...

Current configuration : 12362 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname yourname
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
logging buffered 51200 warnings
!
no aaa new-model
!
crypto pki trustpoint TP-self-signed-2058666588
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2058666588
revocation-check none
rsakeypair TP-self-signed-2058666588
!
!
crypto pki certificate chain TP-self-signed-2058666588
certificate self-signed 01
  3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
  69666963 6174652D 32303538 36363635 3838301E 170D3032 30333031 30303037
  32345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30353836
  36363538 3830819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
  81009631 D109BAE1 ABAAA1DA 4D20C9AC 356ABC3A 27608EED 284101C6 FD7C5C23
  CF86A053 7FD75718 3FD08B79 4C2C61C0 88509B60 B06F8560 3396A172 146209DB
  10EA5A0C 9A28984B 5AE27641 2C96B9EA 4B0057F4 29F08456 4B2EDDA0 3103551D
  5326A059 28A73923 B36CD06B AFBD8BAB C5DBCF83 283DC838 EF399901 F9125AE5
  837B0203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603

551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D
  301F0603 551D2304 18301680 1441E1A4 EDFCD7CB 1F69A2E6 4BA98EC2 CF61151F
  EC301D06 03551D0E 04160414 41E1A4ED FCD7CB1F 69A2E64B A98EC2CF 61151FEC
  300D0609 2A864886 F70D0101 04050003 81810087 775C66B1 BD49BA3D 241FBF65
  58C5D20C FB53C65B C6C510E1 5B6FCA93 0E3412F0 EFC98077 423105F3 5646DF5A
  ED5517AF 65EC46D4 B4F68617 80579861 EB4A86CC 790CA79E C051D4C7 D1EED3F3
  7562A0B2 DF8AC85D 7DF23055 DB397607 97FA886A 5A8F9407 4EFB61F1 8D07634A
  27D0C851 6BD970A6 C48FE5E3 73EAB5F0 D6F3FF
      quit
dot11 syslog
ip source-route
ip dhcp excluded-address x.x.10.1
!
ip dhcp pool ccp-pool
   import all
   network x.x.10.0 255.255.255.248
   default-router x.x.10.1
   lease 0 2
!
!
ip cef
ip domain name yourdomain.com
ip name-server x.x.x.x
ip name-server x.x.x.x
!
!
parameter-map type protocol-info msn-servers
server name messenger.hotmail.com
server name gateway.messenger.hotmail.com
server name webmessenger.msn.com

parameter-map type protocol-info aol-servers
server name login.oscar.aol.com
server name toc.oscar.aol.com
server name oam-d09a.blue.aol.com

parameter-map type protocol-info yahoo-servers
server name scs.msg.yahoo.com
server name scsa.msg.yahoo.com

server name scsb.msg.yahoo.com
server name scsc.msg.yahoo.com
server name scsd.msg.yahoo.com
server name cs16.msg.dcn.yahoo.com
server name cs19.msg.dcn.yahoo.com
server name cs42.msg.dcn.yahoo.com
server name cs53.msg.dcn.yahoo.com
server name cs54.msg.dcn.yahoo.com
server name ads1.vip.scd.yahoo.com
server name radio1.launch.vip.dal.yahoo.com
server name in1.msg.vip.re2.yahoo.com
server name data1.my.vip.sc5.yahoo.com
server name address1.pim.vip.mud.yahoo.com
server name edit.messenger.yahoo.com
server name messenger.yahoo.com
server name http.pager.yahoo.com
server name privacy.yahoo.com
server name csa.yahoo.com
server name csb.yahoo.com
server name csc.yahoo.com

!
!
username admin privilege 15
username garvey privilege 15
!
!
!
archive
log config
  hidekeys
!
!
!
class-map type inspect imap match-any sdm-app-imap
match  invalid-command
class-map type inspect match-any sdm-cls-insp-traffic
match protocol cuseeme
match protocol dns
match protocol ftp
match protocol h323
match protocol https
match protocol icmp
match protocol imap
match protocol pop3
match protocol netshow
match protocol shell
match protocol realmedia
match protocol rtsp
match protocol smtp extended
match protocol sql-net
match protocol streamworks
match protocol tftp
match protocol vdolive
match protocol tcp
match protocol udp
class-map type inspect match-all sdm-insp-traffic
match class-map sdm-cls-insp-traffic
class-map type inspect match-any SDM-Voice-permit
match protocol h323
match protocol skinny
match protocol sip
class-map type inspect msnmsgr match-any sdm-app-msn-otherservices
match  service any
class-map type inspect ymsgr match-any sdm-app-yahoo-otherservices
match  service any
class-map type inspect match-all sdm-protocol-pop3
match protocol pop3
class-map type inspect match-any sdm-cls-icmp-access
match protocol icmp
match protocol tcp
match protocol udp
class-map type inspect match-any sdm-cls-protocol-im
match protocol ymsgr yahoo-servers
match protocol msnmsgr msn-servers
match protocol aol aol-servers
class-map type inspect aol match-any sdm-app-aol-otherservices
class-map type inspect pop3 match-any sdm-app-pop3
match  invalid-command
class-map type inspect http match-any sdm-http-blockparam
match  request port-misuse im
match  request port-misuse p2p
match  req-resp protocol-violation
class-map type inspect match-all sdm-protocol-im
match class-map sdm-cls-protocol-im
class-map type inspect match-all sdm-icmp-access
match class-map sdm-cls-icmp-access
class-map type inspect match-all sdm-invalid-src
match access-group 100
class-map type inspect ymsgr match-any sdm-app-yahoo
match  service text-chat
class-map type inspect msnmsgr match-any sdm-app-msn
match  service text-chat
class-map type inspect http match-any sdm-app-httpmethods
match  request method bcopy
match  request method bdelete
match  request method bmove
match  request method bpropfind
match  request method bproppatch
match  request method connect
match  request method copy
match  request method delete
match  request method edit
match  request method getattribute
match  request method getattributenames
match  request method getproperties
match  request method index
match  request method lock
match  request method mkcol
match  request method mkdir
match  request method move
match  request method notify
match  request method options
match  request method poll
match  request method propfind
match  request method proppatchmatch  service any

match  request method put
match  request method revadd
match  request method revlabel
match  request method revlog
match  request method revnum
match  request method save
match  request method search
match  request method setattribute
match  request method startrev
match  request method stoprev
match  request method subscribe
match  request method trace
match  request method unedit
match  request method unlock
match  request method unsubscribe
class-map type inspect http match-any sdm-http-allowparam
match  request port-misuse tunneling
class-map type inspect match-all sdm-protocol-http
match protocol http
class-map type inspect match-all sdm-protocol-imap
match protocol imap
class-map type inspect aol match-any sdm-app-aol
match  service text-chat
!
!
policy-map type inspect sdm-permit-icmpreply
class type inspect sdm-icmp-access
  inspect
class class-default
  pass
policy-map type inspect http sdm-action-app-http
class type inspect http sdm-http-blockparam
  log
  reset
class type inspect http sdm-app-httpmethods
  log
  reset
class type inspect http sdm-http-allowparam
  log

allow  
policy-map type inspect imap sdm-action-imap
class type inspect imap sdm-app-imap
  log
policy-map type inspect pop3 sdm-action-pop3
class type inspect pop3 sdm-app-pop3
  log
policy-map type inspect im sdm-action-app-im
class type inspect aol sdm-app-aol
  log
  allow
class type inspect msnmsgr sdm-app-msn
  log
  allow
class type inspect ymsgr sdm-app-yahoo
  log
  allow
class type inspect aol sdm-app-aol-otherservices
  log
  reset
class type inspect msnmsgr sdm-app-msn-otherservices
  log
  reset
class type inspect ymsgr sdm-app-yahoo-otherservices
  log
  reset
policy-map type inspect sdm-inspect
class type inspect sdm-invalid-src
  drop log
class type inspect sdm-protocol-http
  inspect
  service-policy http sdm-action-app-http
class type inspect sdm-protocol-imap
  inspect
  service-policy imap sdm-action-imap
class type inspect sdm-protocol-pop3
  inspect
  service-policy pop3 sdm-action-pop3
class type inspect sdm-protocol-iminspect
  service-policy im sdm-action-app-im
class type inspect sdm-insp-traffic
  inspect
class type inspect SDM-Voice-permit
  inspect
class class-default
  pass
policy-map type inspect sdm-permit
class class-default
  drop
!
zone security out-zone
zone security in-zone
zone-pair security sdm-zp-self-out source self destination out-zone
service-policy type inspect sdm-permit-icmpreply
zone-pair security sdm-zp-out-self source out-zone destination self
service-policy type inspect sdm-permit
zone-pair security sdm-zp-in-out source in-zone destination out-zone
service-policy type inspect sdm-inspect
!
!
!
interface ATM0
no ip address
no atm ilmi-keepalive
!
interface ATM0.1 point-to-point
pvc 8/48
  pppoe-client dial-pool-number 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!        
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$
ip address x.x.10.1 255.255.255.248
ip nat inside
ip virtual-reassembly
zone-member security in-zone
ip tcp adjust-mss 1412
!
interface Dialer0
description $FW_OUTSIDE$
ip address negotiated
ip mtu 1452
ip nat outside
ip virtual-reassembly
zone-member security out-zone
encapsulation ppp
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname
ppp chap password
ppp pap sent-username
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
ip nat inside source list 1 interface Dialer0 overload
!
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 10.10.10.0 0.0.0.7
access-list 100 remark SDM_ACL Category=128
access-list 100 permit ip host 255.255.255.255 any
access-list 100 permit ip 127.0.0.0 0.255.255.255 any
dialer-list 1 protocol ip permit
no cdp run

!
!
!
!
control-plane
!
banner exec ^C
% Password expiration warning.
-----------------------------------------------------------------------

Cisco Configuration Professional (Cisco CP) is installed on this device
and it provides the default username "cisco" for  one-time use. If you have
already used the username "cisco" to login to the router and your IOS image
supports the "one-time" user option, then this username has already expired.
You will not be able to login to the router with this username after you exit
this session.

It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.

username <myuser> privilege 15 secret 0 <mypassword>

Replace <myuser> and <mypassword> with the username and password you
want to use.

-----------------------------------------------------------------------
^C
banner login ^C
-----------------------------------------------------------------------
Cisco Configuration Professional (Cisco CP) is installed on this device.
This feature requires the one-time use of the username "cisco" with the
password "cisco". These default credentials have a privilege level of 15.

YOU MUST USE CISCO CP or the CISCO IOS CLI TO CHANGE THESE 
ere are the Cisco IOS commands.

username <myuser>  privilege 15 secret 0 <mypassword>
no username cisco

Replace <myuser> and <mypassword> with the username and password you want
to use.

IF YOU DO NOT CHANGE THE PUBLICLY-KNOWN CREDENTIALS, YOU WILL
NOT BE ABLE TO LOG INTO THE DEVICE AGAIN AFTER YOU HAVE LOGGED OFF.

For more information about Cisco CP please follow the instructions in the
QUICK START GUIDE for your router or go to http://www.cisco.com/go/ciscocp
-----------------------------------------------------------------------
^C
!
line con 0
login local
no modem enable
line aux 0
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
end

So, something is limiting the speed.  Could it be this?

Dialer0 is up, line protocol is up (spoofing)
  Hardware is Unknown
  Description: $FW_OUTSIDE$
  Internet address is x.x.160.62/32
  MTU 1500 bytes, BW 56 Kbit/sec, DLY 20000 usec

What does BW 56 Kbit/sec, DLY 20000 usec mean?

Is this limiting throughput to 56K, if so how do I turn on full speed?  Is there a command to turn all interfaces to full speed?

Any help is really appreciated, thanks in advance.

Andy

4 Replies 4

paolo bevilacqua
Hall of Fame
Hall of Fame

Remove all the ip inspect, qps, etc commands,

vmiller
Level 7
Level 7

You can edit the bandwidth parameter on the dialer. It really won't change anything. The delay parameter is more or less built in.

Both are used by certain routing protocols, they do not have any influence on interface capabilites at the hardware level.

I'd try Paolos suggestions first.

Thanks for the reply.  I was able to get the router to run at full speed, by changing the connection type from PPPoE to PPPoA.  The router is currently running without any firewall configuration.  I tried the 3 different configurations available in SDM (High,medium,low), and with any of these configurations the throughput is reduced to under 1Mbs.  So it seems Paolo is correct.

According to Paolo:

Remove all the ip inspect, qps, etc commands,

Could someone please point me to the documentation to explain what these commands do, and how to remove them.  What effect does removing them have?  Does it lower the security posture by removing these commands?  Why does turning on the firewall drastically reduce the speed?  How do you setup a High security firewall and still get fast throughput?

I would like to setup a firewall policy to let everything from the Lan out to the internet, keep state, and block everything from the internet to the Lan.  Are there any example configs similar to this posted?

Tia


I would like to setup a firewall policy to let everything from the Lan out to the internet, keep state, and block everything from the internet to the Lan.  Are there any example configs similar to this posted?

That is what a simple NAT configuration does. There is no need for any other firewall commands, you are 100% protected.

Please remember to rate useful posts clicking on the stars below.

Review Cisco Networking for a $25 gift card