


 



<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://docwiki.cisco.com/w/skins/common/feed.css?270"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;feed=atom&amp;action=history</id>
		<title>ASA5580-40 TCP Throughput Performance Single Context 4 Interfaces Configuration Example - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;action=history"/>
		<updated>2013-05-21T16:28:04Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.16.0</generator>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;diff=43847&amp;oldid=prev</id>
		<title>Jkratky at 21:34, 18 November 2011</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;diff=43847&amp;oldid=prev"/>
				<updated>2011-11-18T21:34:54Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 21:34, 18 November 2011&lt;/td&gt;
		&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 259:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 259:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp; &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp; &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''Avalanche Load Specifications''' [[Image:TCP Throughput Setup 7.jpg]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''Avalanche Load Specifications''' [[Image:TCP Throughput Setup 7.jpg]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Category: Configuration Examples]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Category: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Security and VPN &lt;/ins&gt;Configuration Examples]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Jkratky</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;diff=32378&amp;oldid=prev</id>
		<title>Jkratky: 1 revision</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;diff=32378&amp;oldid=prev"/>
				<updated>2010-07-27T19:33:32Z</updated>
		
		<summary type="html">&lt;p&gt;1 revision&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 19:33, 27 July 2010&lt;/td&gt;
		&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Jkratky</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;diff=32377&amp;oldid=prev</id>
		<title>Jkratky: /* Procedures */</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=ASA5580-40_TCP_Throughput_Performance_Single_Context_4_Interfaces_Configuration_Example&amp;diff=32377&amp;oldid=prev"/>
				<updated>2010-07-27T19:29:28Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Procedures&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;       &lt;br /&gt;
{| border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; cellpadding=&amp;quot;5&amp;quot; rules=&amp;quot;all&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
{| border=&amp;quot;2&amp;quot; rules=&amp;quot;all&amp;quot; cellpadding=&amp;quot;5&amp;quot; rules=&amp;quot;all&amp;quot;&lt;br /&gt;
| class=&amp;quot;Heading&amp;quot; colspan=&amp;quot;2&amp;quot; | Test Details &amp;lt;font color=&amp;quot;#ffffff&amp;quot;&amp;gt;'''Test Details'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|Goal of Test&lt;br /&gt;
| &lt;br /&gt;
The purpose of this test is to get the maximum throughput the ASA can process using HTTP traffic. This traffic model is more close to the real world traffic.  &lt;br /&gt;
  &lt;br /&gt;
In order to produce the TCP traffic the Spirent Avalanche 2900 was used ( 4, 2900's with 1 ten-gigabit interface each).  When looking at the diagram the numbers 155, 156, 157, 158 are the individual 2900 chassis.  To produce bi-directional traffic through the ASA one client port is placed on the outside pulling a 512K byte object from one server port on the inside, and one client port is placed on the inside pulling a 512K byte object form one server port on the outside. The  Avalanche Tool is configured  with 10672 clients and 16 servers.  This comes down to 667 clients each pointing to one of the 16 servers.  Each client walks an action list of 10 gets to the servers address.  With HTTP 1.1 with persistence this results in 10 transactions per tcp connection.  For each get the server responds with a 512K byte object.  Below are screen shots of the test tool setup. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|Data to Record&lt;br /&gt;
| &lt;br /&gt;
1. ''show cpu'' &amp;lt;br&amp;gt;&lt;br /&gt;
2. ''show conn count'' &amp;lt;br&amp;gt;&lt;br /&gt;
3. ''show io-bridge'' &amp;lt;br&amp;gt;&lt;br /&gt;
4. Capture results from the test tool&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|Estimated Time Needed&lt;br /&gt;
|60 minutes&lt;br /&gt;
|} &lt;br /&gt;
=== Topology ===&lt;br /&gt;
 &lt;br /&gt;
[[Image:TCP_Throughput_4ports.jpg]]&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
=== Procedures ===&lt;br /&gt;
 &lt;br /&gt;
DESCRIPTION&lt;br /&gt;
&lt;br /&gt;
1. On the client side configure (Avalanche Clients):&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
a. 1500 SimUsers for the load on each avalanche 2900&lt;br /&gt;
&lt;br /&gt;
b. 16 subnets,  with 667 hosts (10.100 to 12.254) pointing to one server on the reflector and assign one to each port.&lt;br /&gt;
&lt;br /&gt;
c. 10 GETs on the action profile&lt;br /&gt;
&lt;br /&gt;
2. On the server side, configure: &lt;br /&gt;
&lt;br /&gt;
a. One server per port &lt;br /&gt;
&lt;br /&gt;
b. 512k Object size&lt;br /&gt;
&lt;br /&gt;
3. Bidirectional traffic is used (Clients from the inside to the outside and vice-versa) &amp;lt;br&amp;gt;&lt;br /&gt;
4. While traffic is at steady state take a screen shot of the live Client Stats.&lt;br /&gt;
&lt;br /&gt;
=== Configurations ===&lt;br /&gt;
  &lt;br /&gt;
&amp;lt;pre&amp;gt;ares# sh run&lt;br /&gt;
: Saved&lt;br /&gt;
:&lt;br /&gt;
ASA Version 8.1(1)&lt;br /&gt;
!&lt;br /&gt;
hostname ares&lt;br /&gt;
enable password 8Ry2YjIyt7RRXU24 encrypted&lt;br /&gt;
passwd 2KFQnbNIdI.2KYOU encrypted&lt;br /&gt;
names&lt;br /&gt;
!&lt;br /&gt;
interface Management0/0&lt;br /&gt;
 shutdown&lt;br /&gt;
 no nameif&lt;br /&gt;
 no security-level&lt;br /&gt;
 no ip address&lt;br /&gt;
 management-only&lt;br /&gt;
!&lt;br /&gt;
interface Management0/1&lt;br /&gt;
 shutdown&lt;br /&gt;
 no nameif&lt;br /&gt;
 no security-level&lt;br /&gt;
 no ip address&lt;br /&gt;
 management-only&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet3/0&lt;br /&gt;
 shutdown&lt;br /&gt;
 no nameif   &lt;br /&gt;
 no security-level&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet3/1&lt;br /&gt;
 shutdown&lt;br /&gt;
 no nameif&lt;br /&gt;
 no security-level&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet3/2&lt;br /&gt;
 shutdown&lt;br /&gt;
 no nameif&lt;br /&gt;
 no security-level&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface GigabitEthernet3/3&lt;br /&gt;
 shutdown&lt;br /&gt;
 no nameif&lt;br /&gt;
 no security-level&lt;br /&gt;
 no ip address&lt;br /&gt;
!&lt;br /&gt;
interface TenGigabitEthernet5/0&lt;br /&gt;
 nameif outside_gi_1&lt;br /&gt;
 &lt;br /&gt;
 security-level 0&lt;br /&gt;
 ip address 10.22.0.1 255.255.0.0&lt;br /&gt;
!&lt;br /&gt;
interface TenGigabitEthernet5/1&lt;br /&gt;
 nameif inside_gi_1&lt;br /&gt;
 security-level 100&lt;br /&gt;
 ip address 10.32.0.1 255.255.0.0&lt;br /&gt;
!&lt;br /&gt;
interface TenGigabitEthernet7/0&lt;br /&gt;
 &lt;br /&gt;
 nameif inside_gi_2&lt;br /&gt;
 &lt;br /&gt;
 security-level 100&lt;br /&gt;
 ip addresss 10.20.0.1 255.255.0.0&lt;br /&gt;
!&lt;br /&gt;
interface TenGigabitEthernet7/1&lt;br /&gt;
 nameif outside_gi_2&lt;br /&gt;
 security-level 0&lt;br /&gt;
 ip address 10.30.0.1 255.255.0.0&lt;br /&gt;
!&lt;br /&gt;
ftp mode passive&lt;br /&gt;
access-list in extended permit ip any any&lt;br /&gt;
access-list out extended permit ip any any&lt;br /&gt;
pager lines 24&lt;br /&gt;
logging enable&lt;br /&gt;
logging buffered warnings&lt;br /&gt;
mtu inside_gi 1500&lt;br /&gt;
mtu outside_gi 1500&lt;br /&gt;
no failover&lt;br /&gt;
icmp unreachable rate-limit 1 burst-size 1&lt;br /&gt;
icmp permit any echo inside_gi&lt;br /&gt;
icmp permit any echo-reply inside_gi&lt;br /&gt;
icmp permit any echo outside_gi&lt;br /&gt;
icmp permit any echo-reply outside_gi&lt;br /&gt;
asdm image disk0:/asdm-611.bin&lt;br /&gt;
no asdm history enable&lt;br /&gt;
arp timeout 14400&lt;br /&gt;
access-group out in interface inside_gi_1&lt;br /&gt;
access-group out in interface outside_gi_1&lt;br /&gt;
access-group out in interface inside_gi_2&lt;br /&gt;
access-group out in interface outside_gi_2&lt;br /&gt;
 &lt;br /&gt;
timeout xlate 3:00:00&lt;br /&gt;
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;br /&gt;
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;br /&gt;
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;br /&gt;
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;br /&gt;
dynamic-access-policy-record DfltAccessPolicy&lt;br /&gt;
no snmp-server location&lt;br /&gt;
no snmp-server contact&lt;br /&gt;
snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;br /&gt;
telnet timeout 5&lt;br /&gt;
ssh timeout 5&lt;br /&gt;
console timeout 0&lt;br /&gt;
no threat-detection basic-threat&lt;br /&gt;
no threat-detection statistics access-list&lt;br /&gt;
!&lt;br /&gt;
class-map inspection_default&lt;br /&gt;
 match default-inspection-traffic&lt;br /&gt;
!&lt;br /&gt;
!&lt;br /&gt;
policy-map type inspect dns preset_dns_map&lt;br /&gt;
 parameters&lt;br /&gt;
  message-length maximum 512&lt;br /&gt;
policy-map global_policy&lt;br /&gt;
 class inspection_default&lt;br /&gt;
  inspect dns preset_dns_map&lt;br /&gt;
  inspect ftp&lt;br /&gt;
  inspect h323 h225&lt;br /&gt;
  inspect h323 ras&lt;br /&gt;
  inspect rsh&lt;br /&gt;
  inspect rtsp&lt;br /&gt;
  inspect esmtp&lt;br /&gt;
  inspect sqlnet&lt;br /&gt;
  inspect skinny &lt;br /&gt;
  inspect sunrpc&lt;br /&gt;
  inspect xdmcp&lt;br /&gt;
  inspect sip &lt;br /&gt;
  inspect netbios&lt;br /&gt;
  inspect tftp&lt;br /&gt;
!&lt;br /&gt;
prompt hostname context&lt;br /&gt;
Cryptochecksum:03cbf5e0557d3c2abac442316f5900b1&lt;br /&gt;
: end&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
  &lt;br /&gt;
=== Results ===&lt;br /&gt;
  &lt;br /&gt;
&amp;lt;pre&amp;gt;19,554.443 Mbps incoming to the clients and 299.43Mbps outgoing from the clients.&lt;br /&gt;
A total of 19853.873 of HTTP Throughput were achieved.&lt;br /&gt;
 &lt;br /&gt;
Remember that half the clients were connected on the inside of the ASA, and half the clients on the outside of the ASA, so througput was roughly 9.7 Gig in each direction. !TCP_Throughput_4ports_Results1.JPG|width=32,height=32!\\&lt;br /&gt;
 &lt;br /&gt;
ares# sh cpu&lt;br /&gt;
CPU utilization for 5 seconds = *79%*; 1 minute: 62%; 5 minutes: 21%&lt;br /&gt;
ares# sh conn count&lt;br /&gt;
*1044 in use*, 1049 most used&lt;br /&gt;
ares# sh conn count&lt;br /&gt;
*1044 in use*, 1049 most used&lt;br /&gt;
ares# sh io-bridge&lt;br /&gt;
I/O Bridge-0 slot usage&lt;br /&gt;
&amp;amp;amp;nbsp; Slot 00: 0 pps, 0 bps&lt;br /&gt;
&amp;amp;amp;nbsp; Slot 01: Ignored&lt;br /&gt;
&amp;amp;amp;nbsp; Slot 02: Ignored&lt;br /&gt;
&amp;amp;amp;nbsp; Slot 03: 0 pps, 0 bps&lt;br /&gt;
&amp;amp;amp;nbsp; Slot 04: Ignored&lt;br /&gt;
&amp;amp;amp;nbsp; *Slot 05: 2264848 pps, 19678943960 bps*&lt;br /&gt;
&amp;amp;amp;nbsp; Slot 06: Ignored&lt;br /&gt;
 &lt;br /&gt;
I/O Bridge-1 slot usage&lt;br /&gt;
&amp;amp;amp;nbsp; *Slot 07: 2252144 pps, 19602570400 bps*&lt;br /&gt;
&amp;amp;amp;nbsp; Slot 08: Ignored&lt;br /&gt;
 &lt;br /&gt;
Load distribution - Packets-per-second (10 seconds)&lt;br /&gt;
&amp;amp;amp;nbsp; I/0 Bridge 00:&amp;amp;amp;nbsp; 50%\|************************\*&lt;br /&gt;
&amp;amp;amp;nbsp; I/0 Bridge 01:&amp;amp;amp;nbsp; 50%\|************************\*&lt;br /&gt;
 &lt;br /&gt;
Load distribution - Bits-per-second (10 seconds)&lt;br /&gt;
&amp;amp;amp;nbsp; I/0 Bridge 00:&amp;amp;amp;nbsp; 50%\|************************\*&lt;br /&gt;
&amp;amp;amp;nbsp; I/0 Bridge 01:&amp;amp;amp;nbsp; 50%\|************************\*&lt;br /&gt;
 &lt;br /&gt;
Legend:&lt;br /&gt;
&amp;amp;amp;nbsp; bps - bits per second&lt;br /&gt;
&amp;amp;amp;nbsp; pps - packets per second&amp;amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Screenshots ===&lt;br /&gt;
 &lt;br /&gt;
Test Tool Setup&amp;lt;br&amp;gt;&lt;br /&gt;
'''Spirent Avalanche Network configuration'''&amp;lt;br&amp;gt;&lt;br /&gt;
Client Network Tab  [[Image:TCP Throughput Setup 1.jpg]]&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Server Network Tab [[Image:TCP Throughput Setup 2.jpg]] &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''Spirent Avalanche Client Configuration''' &lt;br /&gt;
  &lt;br /&gt;
Client Associations [[Image:TCP Throughput Setup 3.jpg]] &lt;br /&gt;
Client Action List [[Image:TCP Throughput Setup 4.jpg]] &lt;br /&gt;
&lt;br /&gt;
'''Spirent Avalanche Server Configuration''' &lt;br /&gt;
  &lt;br /&gt;
Server Association [[Image:TCP Throughput Setup 5.jpg]]&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Server Transactions [[Image:TCP Throughput Setup 6.jpg]]&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''Avalanche Load Specifications''' [[Image:TCP Throughput Setup 7.jpg]]&lt;br /&gt;
[[Category: Configuration Examples]]&lt;/div&gt;</summary>
		<author><name>Jkratky</name></author>	</entry>

	</feed>