Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

LDAP queries slow through Pix

I am having an issue where LDAP queries to our Mdaemon Email servers open LDAP directory on our DMZ are extremely slow taking 5 to 10 seconds for a simple name query of 500 users. If I run a query from another host on the dmz it works great, but from the inside firewall interface it is incredably slow. I have all ports enabled outbound to the email server from my subnet, and I have even tried turning off fixup protocol ILS (followed by a clear arp and clear xlate) no change. Any thoughts as to what could be slowing this down?


Re: LDAP queries slow through Pix

Just pointing to another direction !

Have you verified the speed and duplex of the DMZ interface to the Switch ? Often that kind of performance problem is because of duplex miss matches.

Do a " show interface " and check if you have RUNT, CRC or other bad packets on the dmz interface.

Set port to:

auto on Switch / auto on PIX


100full /100Full fixed speed settings



New Member

Re: LDAP queries slow through Pix

Good thought, however I do have both ports set to 100Full and am seeing no errors whatsoever.