Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Performance Problems through PIX

Status
Not open for further replies.

North323

Technical User
Jan 13, 2009
966
0
0
US
i am trying to download a 112mb file through a pix v6.2 and takes about 3 minutes using ftp port 2021. when i do this same test on the network, takes about 20 seconds. in my packet capture i have a ton of these:
incorrect, should be 0x7742 (maybe caused by "TCP checksum offload"?)

could this be the cause of my 'slowness'?
 
Are you FTPing over the internet versus your own LAN?

Burt
 
this does happen over the internet so im trying to rule out my network. the file that i am ftp'ing is on the perimeter device
 
I HIGHLY doubt you have 100MBps speed over the internet...

There is going to be a HUGE difference between the internet and your LAN---what is the confusion? I'm sure I am still not understanding...what are you comparing LAN speed for FTP to???

Burt
 
you are right, i do not have a 100MBps speed over the internet.... here is what i am testing.

ftp download the same 113mb file from different locations within my own network

workstation - 2960 switch dmz 20 second download
workstation - pix firewall - 2960 edge switch 3 minutes 30 seconds

so i am not yet testing over the internet. i am still on my own equipment
 
Still a little confused on your testing scenario nomenclature.

Please restate your testing scenario specifying what PIX model, the level of security that port is set to (LAN, DMZ, WAN), the workstation's job (whether it's the one copying to or being copied from). Also, where is your FTP server at? (public Internet or your DMZ)

Also, have you looked at your speed/duplex settings on the ports involved?
 
workstation - 4500 switch - Pix - Edge Switch I put a ftp server on the Edge switch. trying to ftp from workstation to server(ftp) on the edge and getting horrible download speeds. going through the 'inside' 100 sec to 'outside' 0 PIX version 6.2. Everything is hard coded for 100/full
 
So what happens in that scenario when you remove the PIX altogether since your just testing? Also, you never stated what model of PIX.
 
when i remove the pix from the equation it takes like 20 seconds to ftp down when the pix is in the equation about 3 minutes pix 515 ver 6.2
 
Post a sh run from the PIX. You may want to also post this in the PIX forum...

/
 
found the solution. switch port was set to auto/auto and was negotiating at 10/full
 
Speed/duplex settings are a major culprit a lot of times.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top