Forum Discussion

rezgui_180607's avatar
rezgui_180607
Icon for Nimbostratus rankNimbostratus
May 13, 2016

about the module AsM

Dear all, i have F5 2200 LTM, iwould like to know if i activate the module AMS how many percent can reduce teh perfermance of the f5 ltm?

 

who have some statistic about the consumption for the module ASM?

 

Best Regards

 

11 Replies

  • ASM can dramatically impact the performance. Its hard to nail down numbers because it has a lot to do with what you enable within ASM, what your web pages involve, and what your traffic is like. But on an 8950, I have seen the CPU drop from 100% to 20% during load testing (where we intentionally drove traffic until things broke) by turning off ASM.

     

  • The use of ASM module will not handicap performance of LTM module. What will be affected is the overall performance of your application (page load time). As a rule of thumb, expect at least 15% increase in page load times due to ASM security-checks. If you use poorly configured policies (i.e. apply 'All Signatures', and enable all blocking settings that some do), this performance loss will be greater.

     

    2200s Appliance only has 8GB memory, but with optimized configurations, you can pull off LTM + ASM in low-activity environments. To make a judgement call if you can provision ASM without taking great capacity risks, have a look at your performance graphs. What is your current CPU and Memory usage during peak-activity hours?

     

    • Hannes_Rapp_162's avatar
      Hannes_Rapp_162
      Icon for Nacreous rankNacreous
      Another point: If you use ASM, send the request/blocking logs to external Syslog server. Any kind of on-appliance logging should be avoided.
  • The use of ASM module will not handicap performance of LTM module. What will be affected is the overall performance of your application (page load time). As a rule of thumb, expect at least 15% increase in page load times due to ASM security-checks. If you use poorly configured policies (i.e. apply 'All Signatures', and enable all blocking settings that some do), this performance loss will be greater.

     

    2200s Appliance only has 8GB memory, but with optimized configurations, you can pull off LTM + ASM in low-activity environments. To make a judgement call if you can provision ASM without taking great capacity risks, have a look at your performance graphs. What is your current CPU and Memory usage during peak-activity hours?

     

    • Hannes_Rapp's avatar
      Hannes_Rapp
      Icon for Nimbostratus rankNimbostratus
      Another point: If you use ASM, send the request/blocking logs to external Syslog server. Any kind of on-appliance logging should be avoided.
  • AFAIK, activating the ASM module itself won't add much if any load. The load increase will occur after you've built a policy and begin applying it to your VS's, also dependent upon the traffic level of those VS's. You can keep an eye on exactly how much ASM is adding under Security -> Reporting -> Application -> CPU Utilization. We are running BIG-IP 5000's and I have ASM enabled for over 200 VS's. ASM accounts for between 25-30% of cpu utilization. Total throughput on a single unit is between 350 Mb/s to 400 Mb/s currently.

     

    • John_Buchanan's avatar
      John_Buchanan
      Icon for Nimbostratus rankNimbostratus
      I'm not certain I understand your question. Are you asking at what point will the load from ASM module decrease the appliance's SSL TPS offload performance? That would be a better question for F5 themselves I think, but there would likely be a overall CPU usage threshold beyond which performance would begin to decline.
  • AFAIK, activating the ASM module itself won't add much if any load. The load increase will occur after you've built a policy and begin applying it to your VS's, also dependent upon the traffic level of those VS's. You can keep an eye on exactly how much ASM is adding under Security -> Reporting -> Application -> CPU Utilization. We are running BIG-IP 5000's and I have ASM enabled for over 200 VS's. ASM accounts for between 25-30% of cpu utilization. Total throughput on a single unit is between 350 Mb/s to 400 Mb/s currently.

     

    • John_Buchanan_1's avatar
      John_Buchanan_1
      Icon for Altocumulus rankAltocumulus
      I'm not certain I understand your question. Are you asking at what point will the load from ASM module decrease the appliance's SSL TPS offload performance? That would be a better question for F5 themselves I think, but there would likely be a overall CPU usage threshold beyond which performance would begin to decline.