Forum Discussion

katic_13597's avatar
katic_13597
Icon for Nimbostratus rankNimbostratus
Jul 15, 2007

Performance with SSL ?

I am new to Big-IP ,i am using F5 Big-IP 1500 with 9.1.2 Firmware.

 

we are using SSL Between Client and F5, the architected is as Below:

 

CLient SSL

 

(HTTPS:443) HTTP:995

 

Client ----------> F5BigIP------------->Server

 

 

with above Configurations my Product Performance End to End is like 0.77 Requests Per second , but if we directly hit the Server the Performance is around 17 requests per second , is I am doing wrong over here? Is Port translation from HTTPS :443 to HTTP:995 takes time ? if we use Client SSL and Server SSL my performance is gone ….

 

 

Please help in resolving the issue.

 

 

 

2 Replies

  • Hello,

     

     

    Regardless of the exact syntax you use in the rule, I wouldn't expect anywhere near the slowness you're describing when adding BIG-IP with or without rules to the connection path. I would think there is a application or network layer issue that is causing the slowness. You might try capturing simultaneous tcpdumps on each interface the connections are going over, to get a better idea of what is causing the slowness.

     

     

    Port translation and SSL decryption shouldn't add any noticeable latency to the connections. In fact, if you're decrypting the SSL on the BIG-IP and passing it as HTTP to the web servers, you should normally see a decrease in latency.

     

     

    Unless the traffic is passing over an insecure network between the BIG-IP and the web server, you shouldn't need to re-encrypt the traffic.

     

     

    I'd suggest capturing tcpdumps on the BIG-IP between the client and VIP and BIG-IP and web servers, and look for latency. If you have a support contract you could contact support for help in troubleshooting this issue.

     

     

    Aaron
  • You might try switching your VIP over to straight HTTP and see what your performace is like.

     

     

    Also check your switch port setting. Verify you are set to full 100 or 1000 and there are no errors on the switch port.