03-20-2016 09:30 PM
We have a customer with two sites using ASA 5505's to link them together. They have a 60mb down, 12mb up connection with Comcast at both sites. Their VPN tunnel maxes out around 500kbps. I am looking for ways to try and improve the speed through the tunnel. I am still fairly new at configuring ASA's and do not know exactly where to start trying to diagnose. Any ideas would be greatly appreciated.
03-20-2016 09:38 PM
You might want to tweak MSS/MTU size on the ASAs and clear df-bit on the outside interface of the ASAs as this will allow the packets to be fragmented rather dropped.
Here is a doc to get you started:
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/82444-fragmentation.html
Start off with ping test, as defined in "VPN Encryption Error" section of this document.
Regards,
Dinesh Moudgil
P.S. Please rate helpful posts.
03-21-2016 01:18 AM
Hi
No issues we will be glad to assist you.
May I know if this issue is a new one or just started.
Sh asp
Collect simultaneous captures on both end inside for an application access which is experiencing slowness issue:
-set up capture on ASA:
Cap
Cap drop type asp-drop all
PIX/ASA 7.x and IOS: VPN Fragmentation
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/82444-fragmentation.html
Decrease the MSS to 1300 as discussed
In the ASDM
TCP Maximum Segment Size Overview
http://www.cisco.com/c/en/us/td/docs/security/asa/asa92/asdm72/general/asa-general-asdm/interface-basic.html#pgfId-1887070
Don't Fragment through ASDM
Edit IPsec Pre-Fragmentation Policy
Configuration > VPN > IPsec > Pre-Fragmentation
http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/asdm71/vpn/asdm_71_vpn_config/vpn_asdm_ike.html#pgfId-1006499
Regards,
Aditya
Please rate helpful posts.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide