Skip to content
Notifications
Clear all

Help: IDP is killing my throughput. What are your typical drop numbers?

1 Posts
1 Users
0 Reactions
0 Views
(@chloem)
Estimable Member
Joined: 1 week ago
Posts: 70
Topic starter   [#9250]

I've been running an SRX345 in our lab environment to evaluate Juniper's IDP for a potential deployment. We're looking to replace a standalone IPS appliance. My test setup is a simple file transfer across a site-to-site VPN with IDP in policy-based mode.

My observed throughput drop is more severe than I expected. With IDP disabled, I can saturate our 1Gbps link. Enabling the "Recommended" security policy with the standard Juniper IDP signature set sees throughput fall to around 220-240 Mbps. That's a >75% drop.

I understand there will be a performance impact, but this seems high for our box. I've already verified that traffic is indeed going through the IDP policy and that I'm using the dedicated SPU.

My questions for the community:

* What model SRX are you running, and what's your typical throughput drop when IDP is fully enabled?
* Are you using policy-based or rule-based IDP? Any specific signatures or protocol decryption (like SSL) that you found particularly heavy?
* Besides the obvious (like not inspecting encrypted traffic you can't decrypt), are there any tuning tips that gave you a good balance of performance and security?

My current config highlights:
* SRX345 on Junos 21.4R3
* IDP policy attached via a security policy match
* Using the default "Recommended" IDP policy with no custom signatures yet
* Inspection is on mixed TCP/UDP/ICMP traffic, mostly standard web and SMB protocols



   
Quote