I installed lately a new network interface on PIX-515E, and placed a Citrix server on this new interface(it is configured as DMZ)
since the movement, the application has showed a high delay when loading, and then working normally.
After several troubleshooting, i found that when the user opens a page in the citrix, the database that is kept in the inside ZONE, is upload data to the citrix server in the DMZ data in the rate of 70 to 90 Mbps.
I replaced the PIX with an ASA (100Mbps interfaces) and had the same result, on the upload period, its slow.
Can any1 advice how such a problem could be solved?
Does placing 1GB interfaces (by upgrading the SEC PLUS) on the ASA's inside and dmz zones could solve the delay?
I would try hard coding the speed and duplex settings on both the server and the interface. I also suggest connecting the server to a switchport instead of directly to the PIX/ASA. Drop the PIX/ASA interface into a switchport in the same vlan as the server.
well i went to the client yesterday and did the following test:
Upgraded an ASA to sec plus license, so i had 2 giga interfaces on ethernet 0 and ethernet 1
i plugged this 2 interfaces into giga interfaces of CISCO switch.
SO the inside and DMZ interfaces of the ASA are now operational on a 1 GB bandwidth, and still the same problem, the citrix/scala application opens sometimes fast(1-2 seconds)as it should be, and some times directly after the fast one, the same pages takes about 10-15 seconds to opens.
The number of connections on the ASA is aroung 90 connections at the time of the testing
The CPU is low.
PING from DMZ to Inside (and oppositE) is always < 1ms
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :