[j-nsp] SRX - CPU utilization exceeds

Hugo Slabbert hugo at slabnet.com
Mon Sep 18 15:20:40 EDT 2017


On Mon 2017-Sep-18 10:07:36 +0200, Benoit Plessis <b.plessis at doyousoft.com> 
wrote:

>Le 16/09/2017 à 07:48, sameer mughal a écrit :
>> Hi,
>>
>> Can anyone please review the mentioned below logs and advice me Is this
>> issue critical and how can I fix this ?
>
>Well your firewall is alerting that it is regurlarly out of ressources.
>
>I would check if it's due to something you do (modifying configuration
>at this time),
>or if it's due to external conditions ("attacks" / scan / ..)
>
>Depend on that and on the service impact i would try to simplify
>configuration, update the software
>or more probably start to look at upgrading the device since it kindof
>look inadequat to your need.
>
>Do you have some external monitoring in place with a graphing system to
>look after you firewall ?

This can even just be throughput based, especially for flow services as 
opposed to just packet-mode forwarding.  I've had instances of this from 
e.g. pushing >50-60 Mbps of IPSEC on SRX100 boxes.

-- 
Hugo Slabbert       | email, xmpp/jabber: hugo at slabnet.com
pgp key: B178313E   | also on Signal
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: Digital signature
URL: <https://puck.nether.net/pipermail/juniper-nsp/attachments/20170918/767cb574/attachment.sig>


More information about the juniper-nsp mailing list