I'm experiencing performance problems with our main application after replacing our current firewalls with a new pair of 5525-x's. Basically i'm seeing 50-60ms RTT for our main business application on the old firewalls but when i bring the new ASA's into service the RTT becomes much more erratic (anywhere up to 10000ms response), leading to many complaints from users.
Basic setup is as follows.
Gb0/0 and Gb0/1 Port Channel1 to HP Procurve, Outside Traffic
Gb0/2 and Gb0/3 Port Channel2 to HP Procurve, Inside Vlan, DMZ Vlan and Application Vlan.
Each ASA connects to a seperate HP switch.
Ping from the asa to the gateway on the application vlan seems fine. Application traffic is Inside Vlan to Application Vlan.
I have disabled IPS to rule that out, struggling to see why i'm seeing such erratic traffic.
A little wireshark interrogation shows that we may be retransmitting packets but i'm not sure where to go from here.
Theres very little other traffice through the ASA at the moment, cpu and memory use is mimimal.
Versions are 9.1(2) on the ASA, 11.52 on the HP procurves..
Any ideas where to go on this?