870 slow in lan but fast from the wan to lan, can you help me?

Hello group, thanks for "listen me"! (excuse my english)

I have a cisco 876 dsl o isdn and my server 192.168.1.250 only download from internet at 20kb but the line is de 4mb download and

512kb upload! If a connect with ftp the speed y normally, 200kb/50kb is the problem in nat? can you help me? Thanks

the configuration:

Current configuration : 5159 bytes ! version 12.3 no service pad service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname router ! boot-start-marker boot-end-marker ! enable secret ! no aaa new-model ip subnet-zero ip cef ! ! no ip domain lookup no ftp-server write-enable ! ! ! ! ! ! ! interface BRI0 no ip address shutdown ! interface ATM0 no ip address no ip route-cache cef no ip route-cache no ip mroute-cache no atm auto-configuration no atm ilmi-keepalive no atm address-registration no atm ilmi-enable dsl operating-mode auto hold-queue 208 in ! interface ATM0.1 point-to-point ip address x.x.x.x y.y.y.y ip nat outside ip virtual-reassembly no ip route-cache pvc 8/32 encapsulation aal5snap ! ! interface FastEthernet0 no ip address no cdp enable ! interface FastEthernet1 no ip address ! interface FastEthernet2 no ip address ! interface FastEthernet3 no ip address ! interface Vlan1 ip address 192.168.1.254 255.255.255.0 ip nat inside ip virtual-reassembly ! ip classless ip route 0.0.0.0 0.0.0.0 ATM0.1 ! no ip http server no ip http secure-server ip nat inside source list 1 interface ATM0.1 overload

ip nat inside source static tcp 192.168.1.250 21 x.x.x.x 21 extendable ip nat inside source static tcp 192.168.1.250 25 x.x.x.x 25 extendable ip nat inside source static tcp 192.168.1.250 90 x.x.x.x 80 extendable ip nat inside source static tcp 192.168.1.250 110 x.x.x.x 110 extendable ip nat inside source static tcp 192.168.1.250 4899 x.x.x.x 4899 extendabl e ip nat inside source static tcp 192.168.1.250 9080 x.x.x.x 8080 extendabl e ip nat inside source static tcp 192.168.1.250 9082 x.x.x.x 8082 extendabl e ip nat inside source static tcp 192.168.1.250 9083 x.x.x.x 8083 extendabl e ip nat inside source static tcp 192.168.1.250 9084 x.x.x.x 8084 extendabl e ip nat inside source static tcp 192.168.1.250 9085 x.x.x.x 8085 extendabl e ip nat inside source static tcp 192.168.1.250 9086 x.x.x.x 8086 extendabl e ip nat inside source static tcp 192.168.1.250 9087 x.x.x.x 8087 extendabl e ip nat inside source static tcp 192.168.1.250 9088 x.x.x.x 8088 extendabl e ip nat inside source static tcp 192.168.1.250 9089 x.x.x.x 8089 extendabl e ip nat inside source static tcp 192.168.1.250 9090 x.x.x.x 8090 extendabl e ip nat inside source static tcp 192.168.1.250 9091 x.x.x.x 8091 extendabl e ip nat inside source static tcp 192.168.1.250 9092 x.x.x.x 8092 extendabl e ip nat inside source static tcp 192.168.1.250 9093 x.x.x.x 8093 extendabl e ip nat inside source static tcp 192.168.1.250 9094 x.x.x.x 8094 extendabl e ip nat inside source static tcp 192.168.1.250 9095 x.x.x.x 8095 extendabl e ip nat inside source static tcp 192.168.1.250 9096 x.x.x.x 8096 extendabl e ip nat inside source static tcp 192.168.1.250 9097 x.x.x.x 8097 extendabl e ip nat inside source static tcp 192.168.1.250 9098 x.x.x.x 8098 extendabl e ip nat inside source static tcp 192.168.1.250 9099 x.x.x.x 8099 extendabl e ip nat inside source static tcp 192.168.1.250 9100 x.x.x.x 8100 extendabl e ip nat inside source static tcp 192.168.1.250 9101 x.x.x.x 8101 extendabl e ip nat inside source static tcp 192.168.1.250 9102 x.x.x.x 8102 extendabl e ip nat inside source static tcp 192.168.1.250 9103 x.x.x.x 8103 extendabl e ip nat inside source static tcp 192.168.1.250 9104 x.x.x.x 8104 extendabl e ip nat inside source static tcp 192.168.1.250 9106 x.x.x.x 8106 extendabl e ip nat inside source static tcp 192.168.1.250 9107 x.x.x.x 8107 extendabl e ip nat inside source static tcp 192.168.1.250 9108 x.x.x.x 8108 extendabl e ip nat inside source static tcp 192.168.1.250 9109 x.x.x.x 8109 extendabl e ip nat inside source static tcp 192.168.1.250 9110 x.x.x.x 8110 extendabl e ip nat inside source static tcp 192.168.1.250 9111 x.x.x.x 8111 extendabl e ip nat inside source static tcp 192.168.1.250 9112 x.x.x.x 8112 extendabl e ip nat inside source static tcp 192.168.1.250 9113 x.x.x.x 8113 extendabl e ip nat inside source static tcp 192.168.1.250 9114 x.x.x.x 8114 extendabl e ip nat inside source static tcp 192.168.1.250 9115 x.x.x.x 8115 extendabl e ip nat inside source static tcp 192.168.1.250 9116 x.x.x.x 8116 extendabl e ip nat inside source static tcp 192.168.1.250 9117 x.x.x.x 8117 extendabl e ip nat inside source static tcp 192.168.1.250 8383 x.x.x.x 8383 extendabl e ip nat inside source static tcp 192.168.1.250 9081 x.x.x.x 9081 extendabl e ip nat inside source static tcp 192.168.1.210 10069 x.x.x.x 10069 extenda ble ! access-list 1 permit 192.168.1.0 0.0.0.255 ! control-plane ! ! line con 0 no modem enable transport preferred all transport output all line aux 0 transport preferred all transport output all line vty 0 4 password integral login transport preferred all transport input all transport output all ! scheduler max-task-time 5000 end

Reply to
Euclides
Loading thread data ...

Hey there,

In you config you have:-

interface ATM0 no ip address no ip route-cache cef no ip route-cache no ip mroute-cache

You should enable ip route-cache, ip route-cache cef and ip mroute-cache. Without these enabled, your poor littl 876 will be processing all of the packets. Although - this should not slow it down that much.

LH CCIE#15331

Euclides wrote:

Reply to
Leigh

Thanks Leight, after the change the speed is the slow too. when the server conect from lan (for example download a ftp file or web browser the speed is 18kbs download and upload) but if I download or upload from a remote computer to the server the speed is normally.

Reply to
Euclides

Often when you get -very- slow transfers in one direction, the problem is a duplex mismatch between two devices. If one of the devices thinks that it is running half duplex, and the other one thinks it is running full duplex, then one of the signals will keep detecting that it is colliding (and does not recognize that it is colliding with itself.)

You do not have speed or duplex settings in the configuration you posted, so likely the 870 is expecting to negotiate them. If the attached host (or switch) is instead expecting a fixed speed and fixed full-duplex then the 870 will end up thinking it needs to operate the link at half-duplex. This isn't an 870 bug, it is a limitation on speed and duplex negotiation (below gigabit.)

Reply to
Walter Roberson

Thanks walter but I think that its not the problem.

The server is directly conect to the router. and this server is very fast when the conexion is from wan, for example

ip server: 192.168.1.50 (ftp server, web server etc....)

ip public 876 80.80.80.80

ftp remote server 90.90.90.90

example 1 when the server (192.168.1.50) conecto to ftp 90.90.90.90 a get a file the speed is 20 kb

example 2 when the remote server put THE SAME FILE of example 1: 90.90.90.90 conect to the 80.80.80.80 (the ftp is 192.168.1.50 too but this server don start the conection) is very fast 200 kb

example 3 when the server (192.168.1.50) conecto to ftp 90.90.90.90 a put a file the speed is 20 kb

example 4 when the remote server get THE SAME FILE of example 3: 90.90.90.90 conect to the 80.80.80.80 (the ftp is 192.168.1.50 too but this server don start the conection) is very fast 200 kb

example 5

when a internet user browse a web page in http://80.80.80.80 (the web server is 192.168.1.50 too) the speed is fast

The line is ok (if i use the isp's router the navigation is ok)

Reply to
Euclides

Hola, tengo el mismo problema que t=FA, todo va r=E1pido menos bajar algo de internet, a mi por ejemplo un fichero de Microsoft que con el router del ISP (TIMOF.) baja a 426KB, con el cisco me baja a 20-18 como mucho. Mirando con el SDM (no el sdm express) el consumo de ancho de banda sale que usa el 30%. Como tenemos contrato smartnet, voy a abrir un caso con cisco. Eso s=ED todav=EDa no he probado con el IOS nuevo: c870-advsecurityk9-mz.124-4.T1.bin, ya que el mio vieje con la c870-advsecurityk9-mz.123-8.YI2.bin.

Si logo resolver este problema te lo comunicar=E9, y espero que t=FA me lo digas si lo solucionas antes.

=20

=20

Saludos.

Reply to
bubble

, hoy lo tengo que dejar solucionado o el cliente me mata... puedes mandarme aqui la nueva ios? o a rbermejo7 arroba gmail punto com o si es muy grandre con el servicio

formatting link
lo pruebo y te escribo, al menos he encontado a alguien que le pasa lo mismo! no tengo servicio con cisco contratado :(

gracias por todo, un saludo.

Reply to
Euclides

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.