Forum Discussion
about the module AsM
Dear all, i have F5 2200 LTM, iwould like to know if i activate the module AMS how many percent can reduce teh perfermance of the f5 ltm?
who have some statistic about the consumption for the module ASM?
Best Regards
11 Replies
- mister_paul_717
Nimbostratus
ASM can dramatically impact the performance. Its hard to nail down numbers because it has a lot to do with what you enable within ASM, what your web pages involve, and what your traffic is like. But on an 8950, I have seen the CPU drop from 100% to 20% during load testing (where we intentionally drove traffic until things broke) by turning off ASM.
- Hannes_Rapp_162
Nacreous
The use of ASM module will not handicap performance of LTM module. What will be affected is the overall performance of your application (page load time). As a rule of thumb, expect at least 15% increase in page load times due to ASM security-checks. If you use poorly configured policies (i.e. apply 'All Signatures', and enable all blocking settings that some do), this performance loss will be greater.
2200s Appliance only has 8GB memory, but with optimized configurations, you can pull off LTM + ASM in low-activity environments. To make a judgement call if you can provision ASM without taking great capacity risks, have a look at your performance graphs. What is your current CPU and Memory usage during peak-activity hours?
- Hannes_Rapp_162
Nacreous
Another point: If you use ASM, send the request/blocking logs to external Syslog server. Any kind of on-appliance logging should be avoided.
- Hannes_Rapp
Nimbostratus
The use of ASM module will not handicap performance of LTM module. What will be affected is the overall performance of your application (page load time). As a rule of thumb, expect at least 15% increase in page load times due to ASM security-checks. If you use poorly configured policies (i.e. apply 'All Signatures', and enable all blocking settings that some do), this performance loss will be greater.
2200s Appliance only has 8GB memory, but with optimized configurations, you can pull off LTM + ASM in low-activity environments. To make a judgement call if you can provision ASM without taking great capacity risks, have a look at your performance graphs. What is your current CPU and Memory usage during peak-activity hours?
- Hannes_Rapp
Nimbostratus
Another point: If you use ASM, send the request/blocking logs to external Syslog server. Any kind of on-appliance logging should be avoided.
- John_Buchanan
Nimbostratus
AFAIK, activating the ASM module itself won't add much if any load. The load increase will occur after you've built a policy and begin applying it to your VS's, also dependent upon the traffic level of those VS's. You can keep an eye on exactly how much ASM is adding under Security -> Reporting -> Application -> CPU Utilization. We are running BIG-IP 5000's and I have ASM enabled for over 200 VS's. ASM accounts for between 25-30% of cpu utilization. Total throughput on a single unit is between 350 Mb/s to 400 Mb/s currently.
- rezgui_180607
Nimbostratus
and what about the decrease the number of TPS? - John_Buchanan
Nimbostratus
I'm not certain I understand your question. Are you asking at what point will the load from ASM module decrease the appliance's SSL TPS offload performance? That would be a better question for F5 themselves I think, but there would likely be a overall CPU usage threshold beyond which performance would begin to decline.
- John_Buchanan_1
Altocumulus
AFAIK, activating the ASM module itself won't add much if any load. The load increase will occur after you've built a policy and begin applying it to your VS's, also dependent upon the traffic level of those VS's. You can keep an eye on exactly how much ASM is adding under Security -> Reporting -> Application -> CPU Utilization. We are running BIG-IP 5000's and I have ASM enabled for over 200 VS's. ASM accounts for between 25-30% of cpu utilization. Total throughput on a single unit is between 350 Mb/s to 400 Mb/s currently.
- rezgui_180607
Nimbostratus
and what about the decrease the number of TPS? - John_Buchanan_1
Altocumulus
I'm not certain I understand your question. Are you asking at what point will the load from ASM module decrease the appliance's SSL TPS offload performance? That would be a better question for F5 themselves I think, but there would likely be a overall CPU usage threshold beyond which performance would begin to decline.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com