[j-nsp] SRX - CPU utilization exceeds

sameer mughal pcs.sameer1 at gmail.com
Tue Sep 19 00:26:39 EDT 2017


Hi,

Thanks!

This is SRX Model: srx220h2 - JUNOS Software Release [12.1X46-D35.1] and
traffic is IP not IPSEC. Traffic is IP BGP and route map also configured.
Traffic is pushing around 70 to 80 Mbps.
Please advice.


On Tue, Sep 19, 2017 at 12:20 AM, Hugo Slabbert <hugo at slabnet.com> wrote:

> On Mon 2017-Sep-18 10:07:36 +0200, Benoit Plessis <b.plessis at doyousoft.com>
> wrote:
>
> Le 16/09/2017 à 07:48, sameer mughal a écrit :
>>
>>> Hi,
>>>
>>> Can anyone please review the mentioned below logs and advice me Is this
>>> issue critical and how can I fix this ?
>>>
>>
>> Well your firewall is alerting that it is regurlarly out of ressources.
>>
>> I would check if it's due to something you do (modifying configuration
>> at this time),
>> or if it's due to external conditions ("attacks" / scan / ..)
>>
>> Depend on that and on the service impact i would try to simplify
>> configuration, update the software
>> or more probably start to look at upgrading the device since it kindof
>> look inadequat to your need.
>>
>> Do you have some external monitoring in place with a graphing system to
>> look after you firewall ?
>>
>
> This can even just be throughput based, especially for flow services as
> opposed to just packet-mode forwarding.  I've had instances of this from
> e.g. pushing >50-60 Mbps of IPSEC on SRX100 boxes.
>
> --
> Hugo Slabbert       | email, xmpp/jabber: hugo at slabnet.com
> pgp key: B178313E   | also on Signal
>
> _______________________________________________
> juniper-nsp mailing list juniper-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/juniper-nsp
>


More information about the juniper-nsp mailing list