Hello All,
We have a pair of Cisco 5580-20 ASA's in our DataCenter. As of late we have noticed that when on SSL VPN or IpSEC VPN we lose access to internal resources for a minute or two and then it comes right up. As of late there has been no changes to the ASA or the SSL/IPSec VPN configuration. This problem just showed up unannounced. So far we have rebooted both devices and have failed them over once without having any luck. The problem goes away for a longer period of time (2-5hours) and comes back and just repeats. During that time when I checked out the interface all VPN traffic is coming in I have seen nothing out of the ordinary.
Here is some platform specs:
Platform: ASA5580-20
Version: 8.2.2(16)
SSL VPN Licenses: 750
IPsec VPN Licenses: 10,000
When we experience these problems it is affecting multiple users and when I check the obvious like Memory, CPU, SSL/Ipsec Licenses, it all seems to be in good condition. However I do see some input errors on the interface all traffic is coming in. Since last reboot two days ago it has reported some 427 input errors, and as far as I know input errors are never good. I know that the Cisco 5580-20 has the Maximum Throughput of VPN Connections of 1GB and 2,000.000 Concurrent Sessions. How can I check what the current maximum VPN Throughput is and the Concurrent Sessions?
5580# sh int gi3/0
Interface GigabitEthernet3/0 "Outside", is up, line protocol is up
Hardware is i82571EB 4CU rev06, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is unsupported
Description: Public Internet Space
MAC address 0015.17f2.6b10, MTU 1500
IP address 1.1.1.1, subnet mask 255.255.255.248
585702066 packets input, 469846763095 bytes, 0 no buffer
Received 5239 broadcasts, 0 runts, 0 giants
427 input errors, 0 CRC, 0 frame, 427 overrun, 0 ignored, 0 abort
0 L2 decode drops
490700096 packets output, 265438887717 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 2 interface resets
0 late collisions, 0 deferred
3 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (232/106)
output queue (blocks free curr/low): hardware (255/134)
Traffic Statistics for "Outside":
567789039 packets input, 446968795712 bytes
490700096 packets output, 256498740341 bytes
5194495 packets dropped
1 minute input rate 6870 pkts/sec, 7025703 bytes/sec
1 minute output rate 4904 pkts/sec, 1615554 bytes/sec
1 minute drop rate, 58 pkts/sec
5 minute input rate 7309 pkts/sec, 7500223 bytes/sec
5 minute output rate 5175 pkts/sec, 1697838 bytes/sec
5 minute drop rate, 72 pkts/sec
Has anyone experienced these issues in the past and what the resolution might have been?
Any help is greatly appreciated.
Thanks