ASA Slow IPSec Performance
- by Brent
I have a IPSec link between two sites over ASA 5520s running 8.4(3) and I am getting extremly poor performance when traffic passes over the VPN. CPU on the device is 13%, Memory at 408 MB, and active VPN sessions 2 so the load on the device is particularly low.
Screenshot of wireshark file transfer between the two hosts over the VPN:
The large amount of Header checksum failures is alarming, but I am not sure what to check now. I perf is showing around 4-5 Mbit/sec with differing TCP window sizes.
Show Run on the ASA
http://pastebin.com/uKM4Jh76
Show cry accelerator stats
http://pastebin.com/xQahnqK3