We have one ASA5510 and one Websense as URL filter server. Recently we increased TCP connection number to 40 in order to solve the "URL server down" issue in ASA. Although the error message "URL server down" is gone, the users are still experiencing slow web browsing issue. The "show url-server statistics" still has lots of server time out and retries. Does that mean we still need increase TCP connection number to get rid of Server timeout and retries? Or this is the limitation of ASA when configured with TCP connection with URL filter server? This slow web browsing happened anytime even when not so many users were browsing on very early morning.
We don't have http inspection configured to slow the processing. In addition, someone online said it could be caused by out-of-order http packets. When I show asp drop, I see "TCP Out-of-Order packet buffer timeout" is increasing slowly. It seems not out-of-order packets caused the issue.
Please help. Any idea will be greatly appreciated.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...