cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
27084
Views
0
Helpful
22
Replies

Very slow internet behind ASA5505

sonitadmin
Level 1
Level 1

Recently installed an ASA5505 for a client.  They have Verizon DSL (7mb down, 384up package).  So my config is Verizon (Westell) DSL modem connected to e0/0 (VLAN2) of ASA.  From there I have e0/1 (VLAN1) connected to a 3COM 2250 Plus 50 port switch.

Since installing the ASA client has been complaining of a major slow down in Internet speed.  Contacted ISP and they had me remove the firewall from the equation and hook modem directly to laptop.  With this setup I get between 6-7mb download speeds.  When I put the ASA back into the mix though, the speed drops significantly.  The speed will varry but 90% of the time they do not even get 1mb download speeds.

The configuration is pretty straight forward, not doing a whole lot with the box other then using it for VPN (IPSEC).

I'd really like some suggestions or ideas on what could be causing this or even where to start looking as I am not sure.

Thanks!

22 Replies 22

We agree that you're seeing CRC errors and that should not be. CRC errors are commonly caused by layer 1 problems (cable, NIC, etc) or sometimes layer 2 as well.

While figuring out how to get rid of the CRC errors, I will recommend to move to the 8.x train.

Federico.

Upgraded from 7.2(4) to 8.0(5) this morning.  Here is the latest on the show interface commands:

clientasa# sh int e0/1
Interface Ethernet0/1 "", is up, line protocol is up
  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
        Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
        Available but not configured via nameif
        MAC address 8843.e141.ec6e, MTU not set
        IP address unassigned
        71318 packets input, 25339525 bytes, 0 no buffer
        Received 4677 broadcasts, 0 runts, 0 giants
        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
        0 L2 decode drops
        4 switch ingress policy drops
        79785 packets output, 53670770 bytes, 0 underruns
        0 output errors, 0 collisions, 0 interface resets
        0 babbles, 0 late collisions, 0 deferred
        0 lost carrier, 0 no carrier
        0 input reset drops, 0 output reset drops
        0 rate limit drops
        0 switch egress policy drops
clientasa# sh int e0/1
Interface Ethernet0/1 "", is up, line protocol is up
  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec
        Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
        Available but not configured via nameif
        MAC address 8843.e141.ec6e, MTU not set
        IP address unassigned
        71435 packets input, 25351733 bytes, 0 no buffer
        Received 4691 broadcasts, 0 runts, 0 giants
        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
        0 L2 decode drops
        4 switch ingress policy drops
        79905 packets output, 53684597 bytes, 0 underruns
        0 output errors, 0 collisions, 0 interface resets
        0 babbles, 0 late collisions, 0 deferred
        0 lost carrier, 0 no carrier
        0 input reset drops, 0 output reset drops
        0 rate limit drops
        0 switch egress policy drops

So now I am not seeing any input or CRC errors like I was before, but still having the speed issues.  I did log into the Verizon (Westell 6100) modem this morning to verify speed/duplex settings but I cannot find this anywhere.  I have been searching the Internet for this but have yet to come up with anything.

Not sure where to go from here.

One thing you can check (besides continuining monitoring the interfaces for errors) is check the ouput

of the ''sh asp drop'' on the ASA.

Check if you see any particular process incrementing when experiencing slowliness.

Federico.

Did this problem turn out to be a bad ASA

or trouble with the ISP equipment?

Hi,

The ASA wasn't faulty and a replacement of ISP router fixed the issue.

Thanks.

S

Hi,

I had similar problem which I'll also describe below, but first I'll give the answer that solved mine.

The solution to me was to have the outside interface in "duplex half" !

The problem I had was also very slow internet and in many times I couldn't stream constantly real time video.

I also had MTU 1500 on the outside interface and many CRC errors ....

On one of my brakes at work today I found someone on a website (sorry unknown person for not giving you personaly

the credits ....) but yes removed the duplex full from the outside interface and BOOOOM the speed is here now.

Have a great weekend to all of you.

Cheers,

Ioannis

I have a similar issue. The only different is the ISP original speed. We have 100MB up and down.

We have a fiber internet from AllStream go to a converter to Ethernet signal. This connected to a Cisco 2900 router from the ISP. From this router we connect to a VLAN switch and connect the Cisco ASA5505 to the same VLAN.

In this setup we only have about 10MB/s.

However, as soon as the ASA is removed, the internet speed increased to 80-90MB/s.

I try to replace the VLAN switch (where the ASA5505 and the Cisco 2900 connected to) with a 1 Gigabit switch but the speed still slow.

Is there any answer to this issue yet?

farmsm
Level 1
Level 1

I would make sure that the ADSL modem has had as many services as possible shut down and, if possible, bridge the unit so it does not dole out any DHCP addresses. I had our ISP shut down any firewall services that were running and strip it down to "bare bones" and it seems to have made a difference to us.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card