ScreenOS Firewalls (NOT SRX)
Reply
Contributor
sayjay
Posts: 29
Registered: ‎01-21-2010
0

Unsetting flow-filter porks my ssg140

Why is it that whenever I unset a flow-filter that suddenly my ssg140's CPU spikes essentially killing any throughput for traffic?

 

As we speak right now I can't even ping a directly connected interface from my pc without 5k ms latency.

 

I've noticed this behavior on several of my ssgs.

 

Any help would be appreciated.

 

Thanks!

Recognized Expert
Sahota
Posts: 484
Registered: ‎03-15-2012
0

Re: Unsetting flow-filter porks my ssg140

Hi,

 

What version are you using on SSG140?

Can you share the flow filters that were removed.

 

Regards.

Hardeep

Contributor
sayjay
Posts: 29
Registered: ‎01-21-2010
0

Re: Unsetting flow-filter porks my ssg140

Actually - I think I know what's happening.

 

I think I need to 'undebug all' before remove the flow filter.

 

If I only remove the flow-filter, without turning off the debug, then it probably starts debugging everything.

 

Is my line of thinking correct?

 

Thanks!

Recognized Expert
Sahota
Posts: 484
Registered: ‎03-15-2012
0

Re: Unsetting flow-filter porks my ssg140

Hi,

 

Yes thats true.

As a best practice, once you start a debug, always ensure to immediately turn it off before you start looking into the output.

 

Regards.

Hardeep

Contributor
ed_gpc
Posts: 194
Registered: ‎09-21-2010
0

Re: Unsetting flow-filter porks my ssg140

As a note, just hit ESC key :smileyhappy:

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.