Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > IPsec PIX525 to PIX515 performances.

Reply
Thread Tools

IPsec PIX525 to PIX515 performances.

 
 
AM
Guest
Posts: n/a
 
      10-14-2005
I guys,

I set up an IPsec tunnel between a PIX525 and a PIX515.

They both are behind routers doing NAT. I did everything needed and tunnel estalishes happily.
Performances are very poor. The final segment closest to 515 is wireless
The scenario is as follows:

PIX525(6.3.4)---router837(12.4.2)*----internet-------(wireless connection)----3620(12.3.15)-----PIX515(7.0.2)

First of all I noticed a very weird thing: monitoring interfaces inside and outside of the 515 while transferring a file
over the VPN the amount rate on the outside is doubled than the inside (the PIX525 is working only for the VPN). That
doesn't happen on 525.
Moreover the 3620 often sees its CPU TIME very high (60/80%).

I thought it was an MTU problem, so I decreased it to 1400 on both out and inside interfaces on 515 down to 1400 and on
outside of the 525 as well.

Moreover, monitoring the traffic, the line drawn has a shape very like to \/\/\/\/ on both the PIXes
Maybe the problem is the 3620 but the shape and performances are the same when once in a while the 3620 CPU is not loaded.

Alex.
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
NEED INFO ON IPSec between PIX515 devices. bhumikpatel Hardware 1 12-16-2007 02:59 PM
How to add a second IPSEC tunnel to my PIX515 Johan Beghein Cisco 1 10-03-2007 06:34 PM
PIX515 v.6.2(2) accepts IPSec NAT? Sur Cisco 1 11-22-2005 10:41 AM
PIX525 - Setup ipsec tunnel to two Nortel FW sharing the same subnet iwhite Cisco 3 11-15-2005 01:02 PM
Debugging an IPSec tunnel on PIX515 KR Cisco 5 08-10-2005 06:41 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57