I am having problem on ASA 5540 during FTP data transfer between DMZ's. ASA 5540 is configured one interface for INSIDE, the second for OUTSIDE (internet) and the third interface for three DMZ's by creating subinterfaces. When ever I initiate FTP from INSIDE to one of DMZ's and start data transfer, all other connection from INSIDE to DMZ including traffic to OUTSIDE will be very very slow or some times time out. But when data transfer is finished, every thing will be normal.
I checked the configuration including NAT/PAT, IPS, access-lists but found nothing wrong. show perfmon also shows normal stats. There is also nothing change on memorey or cpu utilization during the problem. When checking connectivity from the ASA it self to DMZ ,it is also pefect. the problem is only on Inter DMZ communication.
Any comment apreciated!
From the captures that you posted. ICMP replies were sent out the inside interface but, your host didn't receive it. Why?
I don' t believe this is a firewall problem. What happens after the replies leave the firewall? Can we run a span on the switch? Is there a layer 3 device on the inside doing some sort of QoS/Policing?