Hey everyone, been lurking for a bit but first time posting. I come from a marketing ops background, so networking isn't my primary domain, but I'm the de facto tech point person for our SaaS company's infra now. We're running a pair of Firepower 2110s in HA.
My team has been complaining about latency on our externally-facing web app portals, especially when we push large content packages or demos. After some digging with our network contractor, we isolated it to the threat inspection on the Firepower. Turning off IPS/IDS on a test policy made the latency vanish, but obviously that's not a solution.
What I'm trying to understand is *why* this seems to be such a known issue. I've read the datasheets and the claimed throughput, but the real-world performance with even a moderate rule set feels... anemic. Our contractor just shrugs and says "that's Firepower," but there has to be more to it.
A few specific things I'm curious about:
* Is the slowness primarily in the initial packet processing, or when a flow is flagged for deeper inspection?
* Does the management style (FDM vs. FMC) play a role in performance overhead?
* I've heard rumors about the architecture – something about a "snort" engine and "flow" versus "proxy" inspection? Could someone ELI5 how that impacts speed?
* Are there specific rule categories or variables (like geolocation) that are known performance killers?
Coming from analytics, I'm used to trade-offs between depth of insight and processing speed. Is this just the trade-off with Firepower, or are we configuring it wrong? Any tuning tips or best practices for rule sets on B2B SaaS traffic would be hugely appreciated. We don't have a ton of video or torrent traffic – mostly HTTPS business app traffic, some SFTP.
Thanks in advance for any insights.
Just here to learn.