Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  NS-25 Max PPS

    Posted 04-28-2009 07:36

    Hi,

     

    Does anyone know what the maximum number of pps (Packets Per Second) is on an NS-25?  We have a box that suffers from high CPU and JTAC informed us that it's because we're pushing close to 5K pps at times and that we should upgrade the box.  Let me know.

     

    Thank you.

     

    -John



  • 2.  RE: NS-25 Max PPS
    Best Answer

    Posted 04-29-2009 00:02

    By high CPU, I am assuming you mean flow portion of the CPU and not task. That said, the biggest determination of flow CPU usage for straight firewalling (no ALG, web filtering, IPSec, etc) is the PPS rate. This is because NS-25 does not use any sort of ASIC like the higher end platforms (NS-500, 5000, ISG). For NS-25 IIRC, maximum firewall performance was 100Mbps (M bits per sec). If we do the math, 100Mbps works out to 12.5MB/s (M bytes per sec) assuming 8 bits per byte. Taking best case scenario of 1500 byte packets, that means 12.5MB/s divided by 1500 equals ~ 8333. This should be a good baseline for what should be maximum PPS rate that he NS-25 can handle.

     

    Assuming that you are exceeding 5000 PPS and also assuming that you may have more than just vanilla firewalling, it is possible that you are reaching the capacity of the box. If that is the case then high flow CPU is expected and I would consider upgrading your hardware to accomodate your traffic needs. 

     

    Note that NS-25 is quite an old platform (more than 6 years old). The replacement for NS-25 which is SSG140 is capable of much greater performance. It more than triples the throughput capacity of the NS-25 (~350Mbps with large packets and 300Mbps of IMIX). 

     

    Hope that helps

    -Richard



  • 3.  RE: NS-25 Max PPS

    Posted 04-29-2009 18:10

    Hi Richard,

     

    That was very helpful, thank you.  I will recommend an upgrade.  However, since the NS-25 is not EOL for a few more years the client may decide to offload some of the traffic to free up resources.  They did this at another site to save money and I see this more and more under this economy.  Thanks again.

     

    -John