Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
starmen2000
Collaborator
Collaborator
Jump to solution

Connection peak exceeded on vsx

Hi mates

 

I'm getting a 'Vsx firewall peak connection exceeded' warning. It has given me this warning twice in two days. The limit is set to 24,000. How can we increase this limit on VSX?

 

Thanks 

0 Kudos
1 Solution

Accepted Solutions
Bob_Zimmerman
Authority
Authority

I would bump it to 250k or more. The point of the hard connections table limit is to protect other VSs on the system from resource exhaustion attacks against one VS. That is, if someone tries to fill up the connections table of your Internet VS, they won't also take down your interior VSs or the VS handling a second Internet connection. Ever since R67 (the first version to move to the 2.6 kernel), the connections table has been able to use many gigabytes of space, so the practical limit for the whole box is generally in the tens of millions of connections.

Unless you're running a hundred VSs on a box, or you're running with very little RAM, tiny tables don't protect you from anything. Instead, they just shoot you in the foot like this over and over as load increases.

View solution in original post

(1)
6 Replies
Alex-
Leader Leader
Leader

You can modify the maximum number of connections in a VS by editing the VS, selecting Optimizations and entering the desired number.

Press OK, then install the policy.

the_rock
Legend
Legend

Below is what @Alex- is referring to. I would strongly suggest you choose automatic option, as gateway itself calculates the amount handles based on cpu/memory.

Andy

 

Screenshot_1.png

0 Kudos
Alex-
Leader Leader
Leader

On VSX, this option is grayed out and you need a manual entry, So if 24K peaks every now and then you could go to 30 or 40K and monitor with either HCP or vsx stat -l.

0 Kudos
the_rock
Legend
Legend

Ah yes, right, I totally forgot about that : - (. I recall back in R77.30, was the same way, pretty sure.

Andy

0 Kudos
Bob_Zimmerman
Authority
Authority

I would bump it to 250k or more. The point of the hard connections table limit is to protect other VSs on the system from resource exhaustion attacks against one VS. That is, if someone tries to fill up the connections table of your Internet VS, they won't also take down your interior VSs or the VS handling a second Internet connection. Ever since R67 (the first version to move to the 2.6 kernel), the connections table has been able to use many gigabytes of space, so the practical limit for the whole box is generally in the tens of millions of connections.

Unless you're running a hundred VSs on a box, or you're running with very little RAM, tiny tables don't protect you from anything. Instead, they just shoot you in the foot like this over and over as load increases.

(1)
genisis__
Leader Leader
Leader

The easiest way to monitor is via SNMP.

I've setup a table which combines Connection Limit, Current connections & Peak Connections.  In this way you can monitor over time.

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events