02-23-2021 03:25 AM
Anyconnect poor performance depending on service provider
Hi all,
I have the following problem with ASA5506 ver asa9-14-2-8-lfbff-k8.
If I connect to a first Internet service provider I have good anyconnect performace for remote user and good Internet access general performance.
If the same firewall is connected to a new service provider only changing public ip address I have unacceptable anyconnet performance for remote user while internet access general performance still good.
this is my webvpn configuration:
webvpn
enable outside
http-headers
hsts-server
enable
max-age 31536000
include-sub-domains
no preload
hsts-client
enable
x-content-type-options
x-xss-protection
content-security-policy
anyconnect image disk0:/anyconnect-win-4.8.03052-webdeploy-k9.pkg 1 regex "Windows NT"
anyconnect image disk0:/anyconnect-win-4.8.03052-webdeploy-k9.pkg 2 regex "Windows CE"
anyconnect image disk0:/anyconnect-linux64-4.5.03040-webdeploy-k9.pkg 3 regex "Linux"
anyconnect image disk0:/anyconnect-macos-4.5.03040-webdeploy-k9.pkg 4 regex "Intel Mac OS X"
anyconnect enable
tunnel-group-list enable
cache
disable
error-recovery disable
I tried with different anyconnect version with the same result.
02-23-2021 03:45 AM
have this new link tested both download and uploads , is the results as expected , for me look like ISP issue rather config for now.
Do some testing without ASA and see you getting expected results.
02-23-2021 03:50 AM
I made many tests. Connection is as exptected with both service provider.
Only anyconnect remote connection by teleworkers doesn't work as expected. Could it be a matter of MTU or TCP-imss?
I also tried to connect directly to the firewall bypassing service provider and all works fine.
On his hand, service provider tested connection using a fortigate firewall and says everithing is ok.
02-23-2021 04:27 AM
If the Links are tested as expected results, next step is tune MTU as you pointed.
02-23-2021 04:30 AM
I don't know how to tune it. Do I have to tune MTU only for anyconnect?
02-23-2021 04:05 AM
Anyconnect would ideally not behave differently for different ISP connections. Here are some pointers on MTU, crypto engine and tunnel optimization features that may help:
Configuring these features should help in Anyconnect optimization. For further investigation, you can use iperf application [https://iperf.fr/] to measure performance with VPN and without vpn(bypassing ASA) and if results are significantly different, engage TAC.
Thank you,
Dinesh Moudgil
P.S. Please rate helpful posts.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide