07-10-2012 05:39 AM
FYI
Apart from the IKE AGL, unless you need to, disable all ALG. It can cause a lot of issues. Streaming video etc.
What is you MSS/MTU Value? What is your WAN connection type?
07-10-2012 05:55 AM
gosi wrote:
moslift wrote:Sebastian, these options i use only on wan interfaces following these recommendations http://jsrx.juniperwiki.com/index.php?title=Syn_Ch
eck
For internal nets i useno syn-check-required; and no sequence-check-required;
Are you expecting asynchronous traffic?
Probably no, are you advise to globally turn off syn-check and sequence-check?
07-10-2012 10:40 AM
moslift wrote:
Probably no, are you advise to globally turn off syn-check and sequence-check?
No, you should be fine. Could you please run flow traceoption to capture the traffic from your slow ftp transfer?
Kind regards,
Sebastian
07-11-2012 11:42 PM
I turned off all ALG and now I have
>show security alg status
ALG Status :
DNS : Disabled
FTP : Disabled
H323 : Disabled
MGCP : Disabled
MSRPC : Disabled
PPTP : Disabled
RSH : Disabled
RTSP : Disabled
SCCP : Disabled
SIP : Disabled
SQL : Disabled
SUNRPC : Disabled
TALK : Disabled
TFTP : Disabled
IKE-ESP : Disabled
But speed ftp downloads still remain at 25-35 kb/sec
I use mtu 1472 and mss 1300. Also set 'path-mtu-discovery'.
WAN connection type - ethernet.
07-11-2012 11:59 PM
07-12-2012 12:18 AM
> show security flow session source-prefix 192.168.0.7 destination-port 21
Session ID: 4496, Policy name: nat_list/6, Timeout: 1764, Valid
In: 192.168.0.7/50189 --> 204.152.184.73/21;tcp, If: ge-0/0/0.0, Pkts: 25, Bytes: 1616
Out: 204.152.184.73/21 --> 62.117.117.20/2065;tcp, If: fe-0/0/2.0, Pkts: 35, Bytes: 2678
Total sessions: 1
Policies are:
from-zone trusted to-zone untrusted {
policy nat_list {
match {
source-address nat_list_set;
destination-address any;
application any;
}
then {
permit {
tcp-options {
syn-check-required;
sequence-check-required;
}
}
}
}
}
default-policy {
deny-all;
}
And I add IP-addresses to nat_list, who need internet access (for example proxy-server).
07-12-2012 12:38 AM
Hi
I am still getting flow FTP from the main freebsd site
Try one of its mirrors
ftp://ftp.uk.freebsd.org/pub/FreeBSD/releases/amd6
My speed went from 300 to 1500KB/s
07-12-2012 12:48 AM
100Mb, link-mode-auto.
I set mtu to 1452, then 1432, then to 1400. Problem still persists.
The command > show interfaces fe-0/0/2
shows me
Link-level type: Ethernet, MTU: 1514, Link-mode: Full-duplex, Speed: 100mbps
But in configuration i set 1452!
What to believe?
07-12-2012 12:54 AM
The Ethernet link MTU is seperate to the IP MSS value. Dont worry about it.
Does any other type of traffic have any speed/preformance issues?
What is te modem/router that the SRX is connected to?
Are you running any UTM on the SRX?
I would still suggest upgrading to 12.1R2.9
07-12-2012 12:59 AM
Also
Run
show interfaces fe-0/0/2 statistics detail
Look for the Input/Output errors