Cisco: FWSM CPU stress test how-to
Sometime ago I had to do a stress test for a Cisco FWSM (Firewall Service Module) to see how the resources are consumed and if some potential traffic can temporarly affect the behavior of this device. For those of you who have don’t know what is a Cisco FWSM, here comes the definition: “Cisco Firewall Services Module (FWSM)—a high-speed, integrated firewall module for Cisco Catalyst 6500 switches and Cisco 7600 Series routers—provides the fastest firewall data rates in the industry: 5-Gbps throughput, 100,000 CPS, and 1M concurrent connections”.
Since I didn’t had a hardware packets generator, I had to use a software one: IPerf . This is a tool that measure the maximum TCP or UDP bandwidth performance. Iperf allows the tuning of various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, datagram loss.Also it can run under Linux, Mac and Windows so the platform shouldn’t be a problem for you. As i said before, I used for testing my notebook as packet generator and a Linux server with DNS service enable as destination. Every packet from source (notebook) to destination (DNS server) was passing through FWSM, where it was inspect at OSI Layer 7 (DNS Application). Please check the topology file to have an idea about the configuration. Please be aware that if the packets (in our case DNS) are not to be inspected by FWSM, than the resource utilization of the FWSM is not so high, even in case of big traffic flow.
Please have a look below for the video presentation of the tutorial:
If you cannot see the video tutorial above, please check this text file which present in text mode everything needed to configure to do a stress test tool.
- http://www.cisco.com Troy
- Florin
Which WAN Optimization vendor will consolidate and expand its market position on 2011
447 votes - Thank you all!I add the results in a blog posts so we can see over years on which [more]
CCIE home rack - Ubuntu persistent net rules
In one of my last posts, I was writing about my CCIE home rack which has one server that runs Ubuntu + [more]
Black Friday 2011 - 50% Off on INE bundles
If anybody is interested in buying INE products, do it now. I've got the following marketing e-mail. The [more]
Free streaming course CCNA 640-802 from INE
I'm sure that a lot of people out there got this info already, but for those who are not part of INE [more]
Home lab for CCIE exam training
Before I started with my preparation I was in front of a dilemma. I knew that I will need a rack to [more]
Professionals Blogs
- routing-bits.com
Close preview
Loading... - bradhedlund.com
Close preview
Loading... - blog.ioshints.info
Close preview
Loading... - CCIECisco
Close preview
Loading... - amyengineer.wordpress.com
Close preview
Loading... - globalconfig.net
Close preview
Loading... - mellowd.co.uk
Close preview
Loading... - Cisco Network Engineer Blog
Close preview
Loading... - danielhertzberg.wordpress.com
Close preview
Loading... - etherealmind.com
Close preview
Loading... - brainbump.net
Close preview
Loading... - blindhog.net
Close preview
Loading... - packetlife.net
Close preview
Loading... - cisco-tips.com
Close preview
Loading... - gns3-labs.com
Close preview
Loading... - packet-forwarding.net
Close preview
Loading... - noshut.blogspot.com
Close preview
Loading...
- routing-bits.com





