Cisco Cisco ASA 5580 Adaptive Security Appliance Fehlerbehebungsanleitung

Seite von 4
      5 minute drop rate, 0 pkts/sec
Sending Traffic to IPS Module
 
When the ASA is configured to send traffic to the IPS module, the TCP stream coalescing feature
is engaged on the ASA. Refer to the 
 section of this document for more information
on the TCP stream coalescing feature.
 
 
ASA Modification of TCP MSS Option Causes Slight Performance Decrease
 
By default the ASA sets the TCP MSS option in the SYN packets to 1380. Therefore, TCP
endpoints should not transmit a TCP segment larger than 1380 bytes. This value is lower than the
often default value of 1460 bytes and represents a TCP performance drop of around six percent
(6%). Performance might improve is you increase the maximum MSS setting on the ASA or
disable the MSS adjustment. Before you modify the default command on the ASA, understand the
risks involved with regard to potential fragmentation if the packet is further encapsulated in the
path somewhere.
 
For more information, refer to the 
section of the Cisco ASA 5500
Series Command Reference.
 
 
Related Information