ASA Slow IPSec Performance

Posted by Brent on Server Fault See other posts from Server Fault or by Brent
Published on 2013-06-26T14:48:30Z Indexed on 2013/06/26 16:22 UTC
Read the original article Hit count: 250

Filed under:
|

I have a IPSec link between two sites over ASA 5520s running 8.4(3) and I am getting extremly poor performance when traffic passes over the VPN. CPU on the device is 13%, Memory at 408 MB, and active VPN sessions 2 so the load on the device is particularly low.

Screenshot of wireshark file transfer between the two hosts over the VPN:

http://i.imgur.com/KfM0Xa4.png

The large amount of Header checksum failures is alarming, but I am not sure what to check now. I perf is showing around 4-5 Mbit/sec with differing TCP window sizes.

Show Run on the ASA

http://pastebin.com/uKM4Jh76

Show cry accelerator stats

http://pastebin.com/xQahnqK3

© Server Fault or respective owner

Related posts about cisco-asa

Related posts about ipsec