3DES fault on VPN PIX 515E 7.0(2) ?

Hi,

I've just found a strange error with a PIX 515E we just comissioned. The pix is used for VPN and firewall in a sub branch of our company. We implemented our tried and trusted 3DES-SHA IKE/IPSEC policies, but this PIX experienced very poor performance from the getgo: amazing packet loss on IMCP packets and pitiful performance over anything encrypted, performance over clear circuits was perfect. I'd run full checks on the configs, and fully debugged all tunnel negotiations, everything was correct and low volume traffic was flowing.

Initially I suspected it might be a line fault, faulty cabling or an MTU issue between the peers causing problems, in the end I tracked it down to the use of 3DES in the IPSEC policy, changing the tunnel policy to use the AES-256 transform set fixed the problems completely, the packet loss went away and performance was exactly as it should be.

Has anyone else seen this before ? I'm considering RMA'ing the box but surely the AES cipher is accelerated by the same logic ?

Any ideas greatly appreciated.

Reply to
I Clark
Loading thread data ...

There are a number of performance bugs which are resolved in 7.1.

If this is a new unit or is under support, you might want to open a case with the Cisco TAC.

Reply to
Merv

Agreed.. thats the next step.

The funny thing is I have a similar box although at revision 7.0(1) which doesn't have the problem, this one has got me very confused.

Reply to
I Clark

Which may mean that a bug has been introduced in 7.0(2) ...

Reply to
Merv

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.