[j-nsp] Juniper SRX assigning IPSec VPN to SPU

Damian Holdcroft damian.holdcroft at gmail.com
Fri Nov 13 23:26:52 EST 2015


I've come across "show security ike tunnel-map", but no command to place
tunnels on a specific SPU.

Deactivating/reactivating ike gateways can cause a tunnel to be reassigned.
Haven't had much luck figuring out a definite pattern to the assignment
though.. thought I had it, then it seemed to change next time I looked at


On Sat, Nov 14, 2015, 02:16 Niklas Hoglund <niklas at hoglund.pp.se> wrote:

> Hi,
> anyone seen if its possible to statically assign a IPSec VPN to a
> particular SPU?
> ... I've seen that its possible to do resource allocation (as per
> http://www.juniper.net/documentation/en_US/junos12.1/topics/concept/logical-system-security-cpu-allocation-control-understanding.html
> )
> but, still I would like to separate "heavy" IPSec VPNs on different SPUs (I
> loose redundancy I understand). When SPU is highly loaded I can see the
> latency going up...
> Should be some (hidden?) command somewhere... =)
> //Regards, Niklas
> _______________________________________________
> juniper-nsp mailing list juniper-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/juniper-nsp

More information about the juniper-nsp mailing list