cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
210
Views
0
Helpful
1
Replies

IOS Firewall 2620 major internet slowdown

Aaron D
Level 1
Level 1

Have T1 to internet. When enabling the firewall the performance slows to a crawl. When removed, we are fine. Any ideas? No http inspection already saw that issue.

thanks

Aaron

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

How many sessions do you have going thru this box? What does a "sho ip inspect stat" command show. If you're plugged into the console when you enable it, do you see a "getting aggressive" message appear, this indicates that the router is seeing too many sessions and is going to start blocking new ones.

On a busy router the default number of connections and half-open connections may not be enough. Try tweaking the following:

> ip inspect max-incomplete high xxxxx

> ip inspect max-incomplete low xxxx

> ip inspect one-minute high xxxx

> ip inspect one-minute low xxxx

and see if you get better results. Use the output of the "sho ip inspect stat" command to figure out how many sessions the router currently has, it can sometimes take a while to get a good value.