12-22-2020 04:01 PM
Hi guys,
Are they any bandwith limitations per SA on IPsec l2l tunnel? Didnt make it more than 300Mbits on an 1Gbits wanlink
Firepower 2140 on both sides
Solved! Go to Solution.
12-23-2020 10:32 AM
Hi i got answer from cisco:
The issue that is mentioned is addressed in the below documentation bug: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp25274
* The FPR and ASA architecture works in a way, that each connection, SA for a better terminology, will utilize one crypto core.
* This means that we will not utilize the whole throughput for only one SA.
* This also means that the throughput in the datasheet is aggregated, meaning this is for ALL SAs.
* In FPR-2140 we’ll have one SA with throughput of ~350 Mbps, and we will keep it this way for each up coming SA, untill we max. out.
Cryptocores on2140 are 16cores
12-22-2020 11:59 PM
Hello,
according to Table 1 in the document linked below, IPSec VPN/L2L throughput should be 2Gbps.
12-23-2020 10:32 AM
Hi i got answer from cisco:
The issue that is mentioned is addressed in the below documentation bug: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp25274
* The FPR and ASA architecture works in a way, that each connection, SA for a better terminology, will utilize one crypto core.
* This means that we will not utilize the whole throughput for only one SA.
* This also means that the throughput in the datasheet is aggregated, meaning this is for ALL SAs.
* In FPR-2140 we’ll have one SA with throughput of ~350 Mbps, and we will keep it this way for each up coming SA, untill we max. out.
Cryptocores on2140 are 16cores
12-23-2020 11:01 AM
Really valuable information, thanks for sharing that !
12-23-2020 01:15 PM
Ure welcome georg stay healthy and inquisitive
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide