 Sailing_Nut
join:2006-11-07 Annapolis, MD
| [Info] Inspection & performance
Hi,
I'm trying to boost my router's performance and I had a question on how much the IP inspection affecte performance and secondly how useful it is.
Here is the inspection section from my config:
|
|
 Sailing_Nut
join:2006-11-07 Annapolis, MD | Should have specified that I'm using an 851w router. |
|
  rolande Certifiable Premium,Mod join:2002-05-24 Powell, OH clubs:
Host: Linksys AT&T Midwest
| reply to Sailing_Nut And you do have it configured on an interface to actually inspect?
Assuming that is the case, you will definitely see a performance hit for doing inspection. It is different on each platform and based on the amount of traffic being passed. Best thing to do is monitor performance for a period of time with it on and then disable it on the interface and monitor for any differences in utilization. It would not be unexpected to see a 10-20% overhead or more in performance from inspection. -- Scott, CCIE #14618 Routing & Switching Ignorance is temporary...stupidity lasts forever! »www.thewaystation.com/techref/tech.shtml »blog.thewaystation.com/ |
|
 Sailing_Nut
join:2006-11-07 Annapolis, MD | The biggest question I have (and didn't actually ask) is "does it affect performance to have inspection turned on for applications that I don't use."
Oh, I do have it set to "ip inspect SDM_LOW out" on my WAN interface.
Thanks! |
|
 aryoba Premium,MVM join:2002-08-22
| Is there any other ip inspect command applied anywhere? I know some people apply ip inspect command on multiple interfaces or on the same interface with "in" and "out" simultaneously.
How about any ACL applied to any interface? If there is ACL on any interface, then it should match with the respective ip inspect command. When they don't match, then there will be performance issue on certain or all applications.
As how useful there are, it depends on how you configure the CBAC security as a whole. When you configure them properly, then you will have some decent security on your servers and the rest of machines within your network seamlessly without affecting performance. |
|
 Sailing_Nut
join:2006-11-07 Annapolis, MD
| I have cleaned tings up in my router but if anything I seem to be experiencing reduced performance.
Si, I guess the best thing would be for me to post my entire config. and hope some of the smart folks here can spot a problem.
|
|
  rolande Certifiable Premium,Mod join:2002-05-24 Powell, OH clubs:
Host: Linksys AT&T Midwest
| Nothing jumps out at me as a glaring issue with your config. What version and feature set of 12.4 IOS are you running? 12.4 is known to have lots of "issues". I personally downgraded one of my own routers to mainline 12.3 to avoid the pain and suffering. I wouldn't call 12.4 anywhere near prime time for deployment. It shouldn't ever hurt to play with new code at home, but in my case it did.  |
|
 Sailing_Nut
join:2006-11-07 Annapolis, MD
| I'm running 12.4(15)T1 on my router.
I'm stretching my memory a bit, but I think I needed to step up to this version because of a feature I'm using, but I can't 100% remember. Either that or the Cisco people tol me I needed to move up to it to solve a problem I was seeing. |
|
 aryoba Premium,MVM join:2002-08-22 | I recall sometime ago you had problem with your DNS server. I don't see the DNS-server-related router configuration anywhere. Therefore I'm not sure if you solve the DNS issue or not. |
|
 Sailing_Nut
join:2006-11-07 Annapolis, MD
| WOW! You have a way better memory than I do!
I think I might be having some DNS problems now. (I'll go back and look for the solution.)
I do know that I'm having lots of problems with web traffic. A while ago I opened a ticket with Cisco & sent them Wire Shark captures. They said it was a problem with my using inspection and that my ISP (Verizon FiOS)was sending lots of out of order packets and that was causing the inspection to puke. |
|
 aryoba Premium,MVM join:2002-08-22
| Without looking at your traffic inspection packet capture, I'm thinking that you may need to punch in line on your ACL 107 and set static PAT for your DNS server performance just like you set one for your FTP server. A lot of time such setup solves a lot of problem. 
Btw, what was the web traffic issue anyway?  |
|
 Sailing_Nut
join:2006-11-07 Annapolis, MD
| Hmmmmm. I didn't think I would need an entry since my DNS server is only a private one and does not have any DNS "duties" that are inbound from the Internet.
My web issues are that sites load slowly or not at all. If a site doesn't load if I refresh in IE it will load very quickly. Sometimes it takes several tries of refreshing to get a site to load.
One other question I just came up with in looking over my config is that I have "ip domain name wtbhome.net" This is not really a public domain name, it is just what I use internally on my network. Could this cause problems? |
|