SRX Services Gateway
Highlighted
SRX Services Gateway

SRX240 Max IPSec VPN's

‎05-24-2017 02:35 PM

Hi All, 

 

Can anyone help out with experiences on SRX240 IPSec VPN tunnels? Specifically the 'actual' maximum number supported? 

 

I posed a question to JTAC to clarify the number (1000 according to the datasheet), and was advised that the total IPSec VPN concurrency was tested without any other feature enabled, and that therefore it may do more, and that the number is theoretical. Thats a bit of a fluffy answer. 

 

We have a customer who currently has 944 on their 240 cluster, and we're obviously wondering just how much further the 240 will go (there are some more tunnels to go on in the near-future). 

 

So, in everyone's experience - 

 

1. Is the 1000 tunnel number a hard limit or theoretical?

2. If it's theorectical, does anyone have experience past 1000 tunnels? if so, how many?

 

Cheers

Andy

PS: Let's just ignore how long it takes to commit that config, shall we? 🙂

7 REPLIES 7
Highlighted
SRX Services Gateway

Re: SRX240 Max IPSec VPN's

‎05-28-2017 05:36 AM

Some limits on the spec sheet are hard coded and some are best estimates based on resources.

 

JTAC is your best source to know for certain which applies in any particular case.

 

For the resource based estimates your milage may vary as you note.  I think the best way to approach this on a particular deploy is to look at the history of the device in question in your network monitoring system for CPU, memory and bandwidth.  As the usage changes over time you can see what the device is actually able to handle in that traffic pattern and configuration.

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Highlighted
SRX Services Gateway

Re: SRX240 Max IPSec VPN's

‎05-28-2017 03:02 PM

Hiya, 

 

Thanks for the response. We don't see a rise in CPU on the cluster (about 20% relatively consistently), RE memory is about 50%, however SPU memory is consistently 50%. 

 

I'm probably happy to accept the 240 will do more than 1000 tunnels. Still interested if anyone has actually breached the number though 🙂 

 

Andy

Highlighted
SRX Services Gateway

Re: SRX240 Max IPSec VPN's

‎05-28-2017 05:20 PM

Are you running A/A or A/P cluster? In A/P all tunnels terminate on the active node. In A/A tunnels can terminate on either node. So I think theoretically speaking, it should be able to easilly accommodate close to 2k concurent tunnels in A/A mode.

[KUDOS PLEASE! If you think I earned it!
If this solution worked for you please flag my post as an "Accepted Solution" so others can benefit..]
Highlighted
SRX Services Gateway

Re: SRX240 Max IPSec VPN's

‎08-21-2017 12:17 AM

Hiya, 

 

Thanks for the response. It's A/P, and actually an A/A cluster would still mean a single SRX supporting more than 1K tunnels in the event of a failure.

 

Best regards

Andy

Highlighted
SRX Services Gateway

Re: SRX240 Max IPSec VPN's

‎12-18-2017 04:47 AM

Hi All, 

This thread is a bit old now, but I thought I'd post the fact that the SRX240 cluster is happy with more than 1000 tunnels. We put another 17 on there this morning and it hasn't fallen into a blackhole. 

 

ipperf@SRX240H2-02> show security ipsec security-associations

node1:

--------------------------------------------------------------------------

  Total active tunnels: 1020

 

Happy days. 


Andy

Highlighted
SRX Services Gateway

Re: SRX240 Max IPSec VPN's

‎12-19-2017 02:26 AM

Thats a great news, thanks for sharing 🙂

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
Highlighted
SRX Services Gateway

Re: SRX240 Max IPSec VPN's

‎11-21-2018 06:30 AM

/me walks into comms room. Pats SRX240 cluster, 'well done old chap!'

 

ipperf@SRX240H2-02> show security ipsec security-associations
node1:
--------------------------------------------------------------------------
Total active tunnels: 1174

 

Impressed as ever!

 

Andy

 

Feedback