IDS/IPS causing network speeds to drop by as much as 80%

Kponte
New here

IDS/IPS causing network speeds to drop by as much as 80%

I have two seperate sites with the same issue.

Site A - Spectrum internet

1068/40 Mbps Is the purchased and delivered speeds at the ISP modem and Router (I tested myself) 

Intrusion detection and prevention - Set to Eitehr Detect or Prevent, Ruleset set to Connecivity, balanced or Security adn the Internet speed drops to 200 Mbps

 

 

Site B - Spectrum internet

600/35 Mbps Is the purchased and delivered speeds at the ISP modem and Router (I tested myself) 

Intrusion detection and prevention - Set to Eitehr Detect or Prevent, Ruleset set to Connecivity, balanced or Security adn the Internet speed drops to 200 Mbps

 

If I set to off, I hit the speeds that are delivered by the ISP (With the limitation of the MX-67 not able to go over 800 Mbps)

 

I want to have the protection, but not at a loss of 80% of the internet speed.  In otehr manufactures of firewalls usually impact the speed by about 20% max.  Please help.  

 

3 Replies 3
ww
Kind of a big deal
Kind of a big deal

Impact of ips is big. I think you could get more speed using more clients/seperate data streams, but max would be like 300/400Mbps

 

https://documentation.meraki.com/MX/MX_Sizing_Information/MX_Sizing_Principles#Performance_Data

 

You could look into using traffic exclusions to get some more throughput on some data sessions

https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Trusted_Traffic_Exclusio...

 

RaphaelL
Kind of a big deal
Kind of a big deal

Exactly what ww said , but what firmware are you running ?

cmr
Kind of a big deal
Kind of a big deal

How many users/devices are at each site?

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels