Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: CPU spikes on data plane caused by security monitoring

$
0
0

 that output, if i'm reading right, suggests a whole lot of packet fragmentation happening, which I believe has to be done by the CPU, rather than any hardare acceleration.

 

Are you running a lot of VPN tunnels, or relying on something like PPPoE for internet that would add additional overhead to a normal full-sized packet?

 

If so, you can look at reducing your tcp-mss for all traffic, and see if that improves anything:

 

set security flow tcp-mss all-tcp mss <value>

 

depending on your scenario the MSS value will need to adjusted for best performance, but you could start as low as 1300 or 1400 and see if that improves matters, and play with the numbers from there.

 

 

-Will


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>