5 pts.
 How to configure session time on ASA 5500 series
I have been running an ASA 5520 in transparent mode on our network. After removing the appliance several users state that they are experiencing increased performance. What could cause this performance increase.

Software/Hardware used:
ASKED: July 29, 2009  6:48 PM
UPDATED: August 4, 2009  6:26 AM

Answer Wiki:
The packet inspection done by the ASA does take some time, and does delay the packets. You could try putting it back in, and then remove the 'inspect' commands one by one, and see which one is causing the most problem, probably the http inspection. Also you may have configured Java inspection or blocking, this also has an effect. If there is a need to firewall within the network, then this delay is the price that is paid for this security. Lan-to-Lan firewalling is almost always going to introduce some delays, dispite what the marketing brochures say ! Otherwise, just firewall on the edge of the network, and ensure that only trusted user equipemtn is connected, and that you have up to date virus and trojan checking installed, and also personal firewalls on the PCs. That should give you a good degree of protection. If you need to restrict access to some areas of the network, you could use VLANs and access control to do this.
Last Wiki Answer Submitted:  August 4, 2009  6:26 am  by  BlankReg   12,245 pts.
All Answer Wiki Contributors:  BlankReg   12,245 pts.
To see all answers submitted to the Answer Wiki: View Answer History.


Discuss This Question:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _