For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Mariappan_S_156's avatar
Mariappan_S_156
Icon for Nimbostratus rankNimbostratus
Jul 03, 2014

APM Slow ISSUE

Hi all,

 

We have been successful complete F5 4000 S as a SSL VPN. Last 10 day we provide access for only 40 users for test purpose that time the user’s not facing slowness issue. But yesterday we had increase the user’s 40 to 140. Suddenly the users are getting slowness issue.

 

Kindly guide us to how to take the issue forward and any tools to analyze this.

 

Mention application is our internal application and this is web and java based application.

 

Thanks Mariappan S

 

7 Replies

  • kunjan's avatar
    kunjan
    Icon for Nimbostratus rankNimbostratus

    If you have enabled debugs during deployment stage, you should turn it off.

     

  • Lucas_Thompson_'s avatar
    Lucas_Thompson_
    Historic F5 Account

    What sort of access methods are in use? Portal Access, Network Access, Application Tunnels, or LTM+APM mode?

     

  • Lucas_Thompson_'s avatar
    Lucas_Thompson_
    Historic F5 Account

    Here are some things you can check:

     

    1- With Network Access, you can choose how to SNAT (nat the client's source IP address). Make sure you're not using that if SMB access is being used. Some Windows Networking filers don't work well when several clients are accessing the same servers with the same source IP. Note that the appropriate SNAT settings are in the Network Access profile, not the Virtual Server. When not using SNAT, make sure you have your Lease Pool off in a different pool of IPs and that your internal routers will route traffic back to BIG-IP for the pool. Ref: http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-network-access-11-4-0/2.html

     

    2- You can use TLS (TCP) or DTLS (UDP) with Network Access. DTLS usually (but not always, depending on ISP conditions) has better performance. DTLS is a safe bet.

     

    3- You can configure Optimized Applications for specific TCP ports (80, 443, etc). Optimized Applications uses a much more efficient transport (isession), and can utilize compression. Ref: http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-network-access-config-11-1-0/3.html

     

    4- As kunjan mentioned, you should check the log levels. Notice is the default log level for Access. Debug should not be used in production except for testing purposes, with special emphasis on Rewrite (Portal Access) and Secure Web Gateway (forward proxy). Ref: http://support.f5.com/kb/en-us/solutions/public/5000/500/sol5532.html

     

    Try these things first. We usually find that complaints of Network Access slowness can be resolved with a combination of these configuration options.