Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Performance Optimization of Juniper SSG20 Firewall

Shulou Source: shulou.com Published: 2022-06-01 03:12:23 10月05日 Update

If you don't make any restrictions, the number of sessions on the firewall can be close to 2000, and then it starts to drop packets, although it is known to be 8064, so it is necessary to optimize the firewall without increasing the cost.

Find the command line documentation and optimize flow first.

early ageout setting:

high watermark = 19 (1532 sessions)

low watermark = 12 (967 sessions)

early ageout = 2

Because the available NATSession is 1600, when the setting reaches 1532, the old session release will be automatically dismantled.

flow initialsession timeout: 20 seconds

Next is optimizing servicetime out

HTTP 6 80 info seeking 1* Pre-defined

HTTP-EXT 6 8000/8001 info seeking 1* Pre-defined

HTTPS 6 443 security 1 Pre-defined

TCP-ANY 6 0/65535 other 1 Pre-defined

UDP-ANY 17 0/65535 other 1* Pre-defined

The last is to directly restrict single IP sessions

SourceIP Based Session Limit

The principle is to keep NATSession below 1600, and then ping the website can not drop the package. The number of sessions is limited to 180.

Tags: Restrictions firewalls fire protection that is necessary next principles commands costs time conditions websites or performance. Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi macOS MariaDB Shulou Tech Info OPPO Reno