Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Support
Technical Documentation
Content Explorer New
 
Enterprise MIBs
 
EOL Documentation
 
File Format Help
 
Glossary
 
Portable Libraries
 
 
Home > Support > Technical Documentation > IDP Series > Tuning the Auto-Recovery Policy Reload Setting
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...
 

Related Documentation

  • Viewing Auto-Recovery Logs
  • Tuning the Auto-Recovery Bypass Setting
  • Disabling the Auto-Recovery Feature
 

Tuning the Auto-Recovery Policy Reload Setting

Problem

The auto-recovery feature detects failure of an IDP engine and buffers packets while it attempts to restart the IDP engine. The auto-recovery process reloads the device configuration, including the security policy. The larger the security policy, the longer it takes to complete the auto-recovery process. By default, packet processing resumes only after the security policy has been reloaded. If your deployment requires faster resumption of traffic flow, you can change this setting so that the IDP engine begins processing traffic before the security policy has been loaded. However, the packets that are processed before the security policy has been loaded are uninspected.

Solution

To set packet processing to resume before the security policy has been loaded:

  1. Log into the CLI as admin and enter su - to switch to root.
  2. Open the /usr/idp/device/bin/user_funcs file in a text editor, such as vi.
  3. Locate the following line:
    export pktprocess_afterpolicyload=1
  4. Change the value to 0 so that packet processing resumes before the security policy has been loaded.
  5. Save the file and exit the editor.
  6. Restart the IDP engine:
    [root@defaulthost admin]# idp.sh restart

    Restarting the IDP engine can take several moments.

 

Related Documentation

  • Viewing Auto-Recovery Logs
  • Tuning the Auto-Recovery Bypass Setting
  • Disabling the Auto-Recovery Feature
 

Published: 2011-09-12

 
  • About Juniper
  • The New Network
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out