01-04-2011 06:57 AM - edited 03-04-2019 10:56 AM
Hi All:
I'm a cisco newb, have many years experience with FreeBSD and OpenBSD administration. I just purchased an 877 ADSL router. After a lot of trial and error, and head-banging, I was able to configure the router through SDM, and connect it to the internet. I still have one major problem, there is something wrong with the speed. I have a 15Mbs DS/800k US ADSL2+ connection. The line works well and I am able to achieve full 15Mb downloads with my current DSL modem/router. However, when I connect with the 877 I can only download around 100-200k. I guess there is a setting that is misconfigured but I don't know where. I would really appreciate some help from the pros here. Below is some info to help debug the problem, if there is something else I need to post please let me know.
----------------------------------------------------------------------------------------------------------------
yourname#show interfaces
ATM0 is up, line protocol is up
Hardware is MPC ATMSAR (with Alcatel ADSL Module)
MTU 4470 bytes, sub MTU 4470, BW 930 Kbit/sec, DLY 390 usec,
reliability 255/255, txload 1/255, rxload 23/255
Encapsulation ATM, loopback not set
Encapsulation(s): AAL5 AAL2, PVC mode
10 maximum active VCs, 1024 VCs per VP, 1 current VCCs
VC Auto Creation Disabled.
VC idle disconnect time: 300 seconds
Last input 00:06:09, output 00:00:09, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/89/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: Per VC Queueing
5 minute input rate 84000 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
3586 packets input, 4401146 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
2310 packets output, 265426 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
ATM0.1 is up, line protocol is up
Hardware is MPC ATMSAR (with Alcatel ADSL Module)
MTU 4470 bytes, BW 930 Kbit/sec, DLY 390 usec,
reliability 255/255, txload 1/255, rxload 23/255
Encapsulation ATM
3675 packets input, 4421483 bytes
2310 packets output, 265426 bytes
0 OAM cells input, 0 OAM cells output
AAL5 CRC errors : 0
AAL5 SAR Timeouts : 0
AAL5 Oversized SDUs : 0
Last clearing of "show interface" counters never
Dialer0 is up, line protocol is up (spoofing)
Hardware is Unknown
reliability 255/255, txload 1/255, rxload 103/255
Encapsulation PPP, loopback not set
Keepalive set (10 sec)
DTR is pulsed for 1 seconds on reset
Interface is bound to Vi1
Last input never, output never, output hang never
Last clearing of "show interface" counters 00:07:45
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: weighted fair
Output queue: 0/1000/64/0 (size/max total/threshold/drops)
Conversations 0/0/16 (active/max active/max total)
Reserved Conversations 0/0 (allocated/max allocated)
Available Bandwidth 42 kilobits/sec
5 minute input rate 59000 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
3561 packets input, 4281548 bytes
2321 packets output, 192950 bytes
Bound to:
Virtual-Access1 is up, line protocol is up
Hardware is Virtual Access interface
MTU 1500 bytes, BW 930 Kbit/sec, DLY 20000 usec,
reliability 255/255, txload 1/255, rxload 16/255
Encapsulation PPP, LCP Open
Open: IPCP
PPPoE vaccess, cloned from Dialer0
Vaccess status 0x44, loopback not set
Keepalive set (10 sec)
DTR is pulsed for 5 seconds on reset
Interface is bound to Di0 (Encapsulation PPP)
Last input 00:01:11, output never, output hang never
Last clearing of "show interface" counters 00:06:59
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 61000 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
3604 packets input, 4281220 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
2333 packets output, 193103 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
0 carrier transitions
FastEthernet0 is up, line protocol is up
Hardware is Fast Ethernet, address is e804.622c.5494 (bia e804.622c.5494)
MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s
ARP type: ARPA, ARP Timeout 04:00:00
Last input never, output never, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 2000 bits/sec, 1 packets/sec
5 minute output rate 52000 bits/sec, 2 packets/sec
4155 packets input, 470340 bytes, 0 no buffer
Received 10 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 input packets with dribble condition detected
4776 packets output, 4299826 bytes, 0 underruns
0 output errors, 0 collisions, 2 interface resets
0 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
FastEthernet1 is up, line protocol is down
Hardware is Fast Ethernet, address is e804.622c.5495 (bia e804.622c.5495)
MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Auto-duplex, Auto-speed
ARP type: ARPA, ARP Timeout 04:00:00
Last input never, output never, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 input packets with dribble condition detected
0 packets output, 0 bytes, 0 underruns
0 output errors, 0 collisions, 2 interface resets
0 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
FastEthernet2 is up, line protocol is down
Hardware is Fast Ethernet, address is e804.622c.5496 (bia e804.622c.5496)
MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Auto-duplex, Auto-speed
ARP type: ARPA, ARP Timeout 04:00:00
Last input never, output never, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 input packets with dribble condition detected
0 packets output, 0 bytes, 0 underruns
0 output errors, 0 collisions, 2 interface resets
0 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 packets output, 0 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
Virtual-Access1 is up, line protocol is up
Hardware is Virtual Access interface
MTU 1500 bytes, BW 930 Kbit/sec, DLY 20000 usec,
reliability 255/255, txload 1/255, rxload 12/255
Encapsulation PPP, LCP Open
Open: IPCP
PPPoE vaccess, cloned from Dialer0
Vaccess status 0x44, loopback not set
Keepalive set (10 sec)
DTR is pulsed for 5 seconds on reset
Interface is bound to Di0 (Encapsulation PPP)
Last input 00:02:30, output never, output hang never
Last clearing of "show interface" counters 00:08:18
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 44000 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
3625 packets input, 4283681 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
2357 packets output, 199946 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
0 carrier transitions
Vlan1 is up, line protocol is up
Hardware is EtherSVI, address is
Description: $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$
Internet address is x.x.10.1/29
MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
DTR is pulsed for 5 seconds on reset
Interface is bound to Di0 (Encapsulation PPP)
Last input 00:02:30, output never, output hang never
Last clearing of "show interface" counters 00:08:18
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 44000 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
3625 packets input, 4283681 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
2357 packets output, 199946 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
0 carrier transitions
Vlan1 is up, line protocol is up
Hardware is EtherSVI, address is e804.622c.5494 (bia e804.622c.5494)
Description: $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$
Internet address is x.x.10.1/29
MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output never, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 1000 bits/sec, 1 packets/sec
5 minute output rate 37000 bits/sec, 1 packets/sec
4255 packets input, 466242 bytes, 0 no buffer
Received 5 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
4376 packets output, 4289012 bytes, 0 underruns
0 output errors, 1 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
yourname#sh ver
Cisco IOS Software, C870 Software (C870-ADVSECURITYK9-M), Version 12.4(24)T4, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Fri 03-Sep-10 17:16 by prod_rel_team
ROM: System Bootstrap, Version 12.3(8r)YI4, RELEASE SOFTWARE
yourname uptime is 19 minutes
System returned to ROM by power-on
System image file is "flash:c870-advsecurityk9-mz.124-24.t4.bin"
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
export@cisco.com.
Cisco 877 (MPC8272) processor (revision 0x400) with 118784K/12288K bytes of memory.
Processor board ID
MPC8272 CPU Rev: Part Number 0xC, Mask Number 0x10
4 FastEthernet interfaces
1 ATM interface
128K bytes of non-volatile configuration memory.
24576K bytes of processor board System flash (Intel Strataflash)
Configuration register is 0x2102
yourname#show dsl interface
ATM0
Alcatel 20190 chipset information
ATU-R (DS) ATU-C (US)
Modem Status: Showtime (DMTDSL_SHOWTIME)
DSL Mode: ITU G.992.5 (ADSL2+) Annex A
ITU STD NUM: 0x03 0x2
Chip Vendor ID: 'STMI' 'IFTN'
Chip Vendor Specific: 0x0000 0x8273
Chip Vendor Country: 0x0F 0xB5
Modem Vendor ID: 'CSCO' ' '
Modem Vendor Specific: 0x0000 0x0000
Modem Vendor Country: 0xB5 0x00
Serial Number Near: FCZ1443C2TE
Serial Number Far:
Modem VerChip ID: C196P (1)
DFE BOM: DFE3.0 Annex A (1)
Capacity Used: 82% 100%
Noise Margin: 14.0 dB 12.5 dB
Output Power: 14.0 dBm 12.5 dBm
Attenuation: 7.0 dB 4.0 dB
FEC ES Errors: 0 0
ES Errors: 1 0
SES Errors: 1 0
LOSES Errors: 1 0
UES Errors: 0 23
Defect Status: None None
Last Fail Code: None
Watchdog Counter: 0xEC
Watchdog Resets: 0
Selftest Result: 0x00
Subfunction: 0x00
Interrupts: 8256 (0 spurious)
PHY Access Err: 0
Activations: 1
LED Status: ON
LED On Time: 100
LED Off Time: 100
Init FW: init_AMR-3.0.014_no_bist.bin
Operation FW: AMR-3.0.014.bin
FW Source: embedded
FW Version: 3.0.14
DS Channel1 DS Channel0 US Channel1 US Channel0
Speed (kbps): 0 18752 0 930
Cells: 0 95522 0 1597792
Reed-Solomon EC: 0 0 0 0
CRC Errors: 0 0 0 0
Header Errors: 0 0 0 0
Total BER: 0E-0 0E-0
Leakage Average BER: 0E-0 0E-0
Interleave Delay: 0 16 0 60
ATU-R (DS) ATU-C (US)
Bitswap: enabled enabled
Bitswap success: 0 0
Bitswap failure: 0 0
LOM Monitoring : Disabled
DMT Bits Per Bin
000: 0 0 0 0 0 0 2 3 5 6 7 8 9 9 A B
010: B B C C C C C C C C C C C C B B
020: 0 8 9 9 A B C C C C C D D D D D
030: D D E E E E E E E E E E E E E E
040: E E E E E E E E E E E E E E E E
050: E E E E E E E E E E E E E E E E
060: E E D D D 2 D D D D D D D D D D
070: D D C C D C C C C C C C C B C C
080: C C C C C C C C C D D D D D D D
090: D D D D D D D D D D D D D C C C
0A0: C C C C C C C C C C C C C C B B
0B0: B B B B B B B B B B B B B B B B
0C0: C C C C C C C C C C C C C C C C
0D0: C C C C C C C C C C C C C C C C
0E0: C C C C C C C C C C C C C C C C
0F0: C C C C C C C C C C C C C C C C
100: C C C C C C C C C C C C C C C C
110: C C C C C C C C C C C C C C C C
120: C C C C C C C C C C C C C C C C
130: C C C C C C C C C C C C C C C C
LOM Monitoring : Disabled
DMT Bits Per Bin
000: 0 0 0 0 0 0 2 3 5 6 7 8 9 9 A B
010: B B C C C C C C C C C C C C B B
020: 0 8 9 9 A B C C C C C D D D D D
030: D D E E E E E E E E E E E E E E
040: E E E E E E E E E E E E E E E E
050: E E E E E E E E E E E E E E E E
060: E E D D D 2 D D D D D D D D D D
070: D D C C D C C C C C C C C B C C
080: C C C C C C C C C D D D D D D D
090: D D D D D D D D D D D D D C C C
0A0: C C C C C C C C C C C C C C B B
0B0: B B B B B B B B B B B B B B B B
0C0: C C C C C C C C C C C C C C C C
0D0: C C C C C C C C C C C C C C C C
0E0: C C C C C C C C C C C C C C C C
0F0: C C C C C C C C C C C C C C C C
100: C C C C C C C C C C C C C C C C
110: C C C C C C C C C C C C C C C C
120: C C C C C C C C C C C C C C C C
130: C C C C C C C C C C C C C C C C
140: C C C C C C C C C C C C C C C C
150: C C C C C C C C C C C C C C C B
160: B B B B B B B B B B B B B B B B
170: B B B B B B A A A A A A A A A A
180: A A A A A A A A A A A A A A A A
190: A A A A 9 9 9 9 A 9 9 9 9 9 9 9
1A0: 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9
1B0: A A A 9 9 A A 9 9 A 9 A 9 A A A
1C0: 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9
1D0: 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9 9
1E0: 9 9 9 9 9 9 9 9 9 9 9 8 8 8 8 8
1F0: 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8
DSL: Training log buffer capability is not enabled
yourname# show running-config
Building configuration...
Current configuration : 12362 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname yourname
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
logging buffered 51200 warnings
!
no aaa new-model
!
crypto pki trustpoint TP-self-signed-2058666588
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2058666588
revocation-check none
rsakeypair TP-self-signed-2058666588
!
!
crypto pki certificate chain TP-self-signed-2058666588
certificate self-signed 01
3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 32303538 36363635 3838301E 170D3032 30333031 30303037
32345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30353836
36363538 3830819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
81009631 D109BAE1 ABAAA1DA 4D20C9AC 356ABC3A 27608EED 284101C6 FD7C5C23
CF86A053 7FD75718 3FD08B79 4C2C61C0 88509B60 B06F8560 3396A172 146209DB
10EA5A0C 9A28984B 5AE27641 2C96B9EA 4B0057F4 29F08456 4B2EDDA0 3103551D
5326A059 28A73923 B36CD06B AFBD8BAB C5DBCF83 283DC838 EF399901 F9125AE5
837B0203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603
551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D
301F0603 551D2304 18301680 1441E1A4 EDFCD7CB 1F69A2E6 4BA98EC2 CF61151F
EC301D06 03551D0E 04160414 41E1A4ED FCD7CB1F 69A2E64B A98EC2CF 61151FEC
300D0609 2A864886 F70D0101 04050003 81810087 775C66B1 BD49BA3D 241FBF65
58C5D20C FB53C65B C6C510E1 5B6FCA93 0E3412F0 EFC98077 423105F3 5646DF5A
ED5517AF 65EC46D4 B4F68617 80579861 EB4A86CC 790CA79E C051D4C7 D1EED3F3
7562A0B2 DF8AC85D 7DF23055 DB397607 97FA886A 5A8F9407 4EFB61F1 8D07634A
27D0C851 6BD970A6 C48FE5E3 73EAB5F0 D6F3FF
quit
dot11 syslog
ip source-route
ip dhcp excluded-address x.x.10.1
!
ip dhcp pool ccp-pool
import all
network x.x.10.0 255.255.255.248
default-router x.x.10.1
lease 0 2
!
!
ip cef
ip domain name yourdomain.com
ip name-server x.x.x.x
ip name-server x.x.x.x
!
!
parameter-map type protocol-info msn-servers
server name messenger.hotmail.com
server name gateway.messenger.hotmail.com
server name webmessenger.msn.com
parameter-map type protocol-info aol-servers
server name login.oscar.aol.com
server name toc.oscar.aol.com
server name oam-d09a.blue.aol.com
parameter-map type protocol-info yahoo-servers
server name scs.msg.yahoo.com
server name scsa.msg.yahoo.com
server name scsb.msg.yahoo.com
server name scsc.msg.yahoo.com
server name scsd.msg.yahoo.com
server name cs16.msg.dcn.yahoo.com
server name cs19.msg.dcn.yahoo.com
server name cs42.msg.dcn.yahoo.com
server name cs53.msg.dcn.yahoo.com
server name cs54.msg.dcn.yahoo.com
server name ads1.vip.scd.yahoo.com
server name radio1.launch.vip.dal.yahoo.com
server name in1.msg.vip.re2.yahoo.com
server name data1.my.vip.sc5.yahoo.com
server name address1.pim.vip.mud.yahoo.com
server name edit.messenger.yahoo.com
server name messenger.yahoo.com
server name http.pager.yahoo.com
server name privacy.yahoo.com
server name csa.yahoo.com
server name csb.yahoo.com
server name csc.yahoo.com
!
!
username admin privilege 15
username garvey privilege 15
!
!
!
archive
log config
hidekeys
!
!
!
class-map type inspect imap match-any sdm-app-imap
match invalid-command
class-map type inspect match-any sdm-cls-insp-traffic
match protocol cuseeme
match protocol dns
match protocol ftp
match protocol h323
match protocol https
match protocol icmp
match protocol imap
match protocol pop3
match protocol netshow
match protocol shell
match protocol realmedia
match protocol rtsp
match protocol smtp extended
match protocol sql-net
match protocol streamworks
match protocol tftp
match protocol vdolive
match protocol tcp
match protocol udp
class-map type inspect match-all sdm-insp-traffic
match class-map sdm-cls-insp-traffic
class-map type inspect match-any SDM-Voice-permit
match protocol h323
match protocol skinny
match protocol sip
class-map type inspect msnmsgr match-any sdm-app-msn-otherservices
match service any
class-map type inspect ymsgr match-any sdm-app-yahoo-otherservices
match service any
class-map type inspect match-all sdm-protocol-pop3
match protocol pop3
class-map type inspect match-any sdm-cls-icmp-access
match protocol icmp
match protocol tcp
match protocol udp
class-map type inspect match-any sdm-cls-protocol-im
match protocol ymsgr yahoo-servers
match protocol msnmsgr msn-servers
match protocol aol aol-servers
class-map type inspect aol match-any sdm-app-aol-otherservices
class-map type inspect pop3 match-any sdm-app-pop3
match invalid-command
class-map type inspect http match-any sdm-http-blockparam
match request port-misuse im
match request port-misuse p2p
match req-resp protocol-violation
class-map type inspect match-all sdm-protocol-im
match class-map sdm-cls-protocol-im
class-map type inspect match-all sdm-icmp-access
match class-map sdm-cls-icmp-access
class-map type inspect match-all sdm-invalid-src
match access-group 100
class-map type inspect ymsgr match-any sdm-app-yahoo
match service text-chat
class-map type inspect msnmsgr match-any sdm-app-msn
match service text-chat
class-map type inspect http match-any sdm-app-httpmethods
match request method bcopy
match request method bdelete
match request method bmove
match request method bpropfind
match request method bproppatch
match request method connect
match request method copy
match request method delete
match request method edit
match request method getattribute
match request method getattributenames
match request method getproperties
match request method index
match request method lock
match request method mkcol
match request method mkdir
match request method move
match request method notify
match request method options
match request method poll
match request method propfind
match request method proppatchmatch service any
match request method put
match request method revadd
match request method revlabel
match request method revlog
match request method revnum
match request method save
match request method search
match request method setattribute
match request method startrev
match request method stoprev
match request method subscribe
match request method trace
match request method unedit
match request method unlock
match request method unsubscribe
class-map type inspect http match-any sdm-http-allowparam
match request port-misuse tunneling
class-map type inspect match-all sdm-protocol-http
match protocol http
class-map type inspect match-all sdm-protocol-imap
match protocol imap
class-map type inspect aol match-any sdm-app-aol
match service text-chat
!
!
policy-map type inspect sdm-permit-icmpreply
class type inspect sdm-icmp-access
inspect
class class-default
pass
policy-map type inspect http sdm-action-app-http
class type inspect http sdm-http-blockparam
log
reset
class type inspect http sdm-app-httpmethods
log
reset
class type inspect http sdm-http-allowparam
log
allow
policy-map type inspect imap sdm-action-imap
class type inspect imap sdm-app-imap
log
policy-map type inspect pop3 sdm-action-pop3
class type inspect pop3 sdm-app-pop3
log
policy-map type inspect im sdm-action-app-im
class type inspect aol sdm-app-aol
log
allow
class type inspect msnmsgr sdm-app-msn
log
allow
class type inspect ymsgr sdm-app-yahoo
log
allow
class type inspect aol sdm-app-aol-otherservices
log
reset
class type inspect msnmsgr sdm-app-msn-otherservices
log
reset
class type inspect ymsgr sdm-app-yahoo-otherservices
log
reset
policy-map type inspect sdm-inspect
class type inspect sdm-invalid-src
drop log
class type inspect sdm-protocol-http
inspect
service-policy http sdm-action-app-http
class type inspect sdm-protocol-imap
inspect
service-policy imap sdm-action-imap
class type inspect sdm-protocol-pop3
inspect
service-policy pop3 sdm-action-pop3
class type inspect sdm-protocol-iminspect
service-policy im sdm-action-app-im
class type inspect sdm-insp-traffic
inspect
class type inspect SDM-Voice-permit
inspect
class class-default
pass
policy-map type inspect sdm-permit
class class-default
drop
!
zone security out-zone
zone security in-zone
zone-pair security sdm-zp-self-out source self destination out-zone
service-policy type inspect sdm-permit-icmpreply
zone-pair security sdm-zp-out-self source out-zone destination self
service-policy type inspect sdm-permit
zone-pair security sdm-zp-in-out source in-zone destination out-zone
service-policy type inspect sdm-inspect
!
!
!
interface ATM0
no ip address
no atm ilmi-keepalive
!
interface ATM0.1 point-to-point
pvc 8/48
pppoe-client dial-pool-number 1
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$
ip address x.x.10.1 255.255.255.248
ip nat inside
ip virtual-reassembly
zone-member security in-zone
ip tcp adjust-mss 1412
!
interface Dialer0
description $FW_OUTSIDE$
ip address negotiated
ip mtu 1452
ip nat outside
ip virtual-reassembly
zone-member security out-zone
encapsulation ppp
dialer pool 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname
ppp chap password
ppp pap sent-username
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Dialer0
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
ip nat inside source list 1 interface Dialer0 overload
!
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 10.10.10.0 0.0.0.7
access-list 100 remark SDM_ACL Category=128
access-list 100 permit ip host 255.255.255.255 any
access-list 100 permit ip 127.0.0.0 0.255.255.255 any
dialer-list 1 protocol ip permit
no cdp run
!
!
!
!
control-plane
!
banner exec ^C
% Password expiration warning.
-----------------------------------------------------------------------
Cisco Configuration Professional (Cisco CP) is installed on this device
and it provides the default username "cisco" for one-time use. If you have
already used the username "cisco" to login to the router and your IOS image
supports the "one-time" user option, then this username has already expired.
You will not be able to login to the router with this username after you exit
this session.
It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.
username <myuser> privilege 15 secret 0 <mypassword>
Replace <myuser> and <mypassword> with the username and password you
want to use.
-----------------------------------------------------------------------
^C
banner login ^C
-----------------------------------------------------------------------
Cisco Configuration Professional (Cisco CP) is installed on this device.
This feature requires the one-time use of the username "cisco" with the
password "cisco". These default credentials have a privilege level of 15.
YOU MUST USE CISCO CP or the CISCO IOS CLI TO CHANGE THESE
ere are the Cisco IOS commands.
username <myuser> privilege 15 secret 0 <mypassword>
no username cisco
Replace <myuser> and <mypassword> with the username and password you want
to use.
IF YOU DO NOT CHANGE THE PUBLICLY-KNOWN CREDENTIALS, YOU WILL
NOT BE ABLE TO LOG INTO THE DEVICE AGAIN AFTER YOU HAVE LOGGED OFF.
For more information about Cisco CP please follow the instructions in the
QUICK START GUIDE for your router or go to http://www.cisco.com/go/ciscocp
-----------------------------------------------------------------------
^C
!
line con 0
login local
no modem enable
line aux 0
line vty 0 4
privilege level 15
login local
transport input telnet ssh
!
scheduler max-task-time 5000
end
So, something is limiting the speed. Could it be this?
Dialer0 is up, line protocol is up (spoofing)
Hardware is Unknown
Description: $FW_OUTSIDE$
Internet address is x.x.160.62/32
MTU 1500 bytes, BW 56 Kbit/sec, DLY 20000 usec
What does BW 56 Kbit/sec, DLY 20000 usec mean?
Is this limiting throughput to 56K, if so how do I turn on full speed? Is there a command to turn all interfaces to full speed?
Any help is really appreciated, thanks in advance.
Andy
01-04-2011 05:48 PM
Remove all the ip inspect, qps, etc commands,
01-05-2011 07:54 AM
You can edit the bandwidth parameter on the dialer. It really won't change anything. The delay parameter is more or less built in.
Both are used by certain routing protocols, they do not have any influence on interface capabilites at the hardware level.
I'd try Paolos suggestions first.
01-05-2011 03:52 PM
Thanks for the reply. I was able to get the router to run at full speed, by changing the connection type from PPPoE to PPPoA. The router is currently running without any firewall configuration. I tried the 3 different configurations available in SDM (High,medium,low), and with any of these configurations the throughput is reduced to under 1Mbs. So it seems Paolo is correct.
According to Paolo:
Remove all the ip inspect, qps, etc commands,
Could someone please point me to the documentation to explain what these commands do, and how to remove them. What effect does removing them have? Does it lower the security posture by removing these commands? Why does turning on the firewall drastically reduce the speed? How do you setup a High security firewall and still get fast throughput?
I would like to setup a firewall policy to let everything from the Lan out to the internet, keep state, and block everything from the internet to the Lan. Are there any example configs similar to this posted?
Tia
01-06-2011 11:01 AM
I would like to setup a firewall policy to let everything from the Lan out to the internet, keep state, and block everything from the internet to the Lan. Are there any example configs similar to this posted?
That is what a simple NAT configuration does. There is no need for any other firewall commands, you are 100% protected.
Please remember to rate useful posts clicking on the stars below.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide