05-02-2011 11:27 AM - edited 03-04-2019 12:14 PM
Hi All,
having a very strange problem with a Cisco 1861 running - Cisco IOS Software, C1861 Software (C1861-ADVENTERPRISEK9-M), Version 12.4(24)T5
The issue -
I have suddenly started to get performance issues with downloads and access through the ZBF. Without the firewall enabled and just having NAT enabled and routing , downloads perform as expected - ( have been using Itunes download as test file ) - with the ZBF enabled , and the necessary rules installed to inspect & allow traffic - downloads stall - and the only way to get the downlaod to start again is to pause , then resume. The stalls are anything between the first 25 - 120 secs.
I have debugged and performed packet traces - but cant see anything untoward. I have also placed another router ( just a cheap Belkin ) on the ADSL service and again , the downloads work as expected.
one further thing to add is that when im tunneling through the firewall ( VPN ) , then downloads do work as expected - suggesting that the issue is with native HTTP(s) traffic......
I have upgraded from T4 to T5 - and the symptons still remain - I am thinking that these may have been introduced when i upgraded to T4 a few monthes ago.
any help would be gratefully appreicated.....
cheers
Nick
05-02-2011 11:38 AM
It is known that IOS "firewall" has major performance issues. Just remove it, it's useless anyway.
07-11-2011 04:58 PM
Greetings All,
I have a client that is using a 2801 with ZBF and they are having a similar issue. A file larger then 20Mb will start off downloading and with in 10-40 seconds you can see the transfer rate just tumble in to self termination after a time. There was mention of a known issue has there been a fix yet or work around? 15.x??
Cheers,
Mike
07-12-2011 12:45 AM
Hello Nick, Michael,
If you try removing HTTP inspection and use only TCP inspection, is it the same?
I know that there were some issues with HTTP inspection with ZBF due to out of order packets. There was also a bug opened for a performance issue on ZBF and HTTP: CSCta95621 which is indeed fixed in 15.0M.
If you need ZBF, it might be worth trying either TCP inspection or an upgrade.
Warm Regards,
Rose
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide