The 2611XL is supposed to be able to forward 20k pps. Even with small packets, that's still over 10 Mbps so I thought it would make a suitable firewall for a school with about 300 students and a 10Mbps link to the Internet.
I attempted to configure IP Inspection (for the first time ever) on this box and internet throughput dropped from 5 Mbps to under 1 Mbps. Is this to be expected with this router, or is my configuration flawed (or both)?
ip inspect name myfw http ip inspect name myfw smtp ip inspect name myfw tcp ip inspect name myfw udp
interface FastEthernet0/0 ip address x.y.235.18 255.255.255.252 ip access-group block-out2in in ip nat outside ip inspect myfw out duplex auto speed auto ! interface FastEthernet0/1 ip address 10.0.0.1 255.255.255.0 ip nat inside speed 100 full-duplex
ip access-list extended block-out2in permit icmp any any echo-reply permit icmp any any unreachable permit icmp any any time-exceeded permit icmp any any packet-too-big permit icmp any any traceroute deny ip 10.0.0.0 0.255.255.255 any log-input deny ip host 255.255.255.255 any log-input deny ip any any