weight

Syntax

weight {equal;firewall;idp;}

Hierarchy Level

[edit security forwarding-process application-services maximize-idp-sessions]]

Release Information

Statement introduced in Release 9.6 of Junos OS.

Description

If you are deploying IDP policies, you can tune the device to increase IDP session capacity. By using the provided commands to change the way the system allocates resources, you can achieve a higher IDP session capacity.

Devices ship with an implicit default session capacity setting. This default value gives more weight to firewall sessions. You can manually override the default by using the maximize-idp-sessions command. The command allows you to choose between these weight values: equal, firewall, and IDP. The following table displays the available session capacity weight and approximate throughput for each.

Table 5: Session Capacity and Resulting Throughput

Weight Value

Firewall Capacity

IDP Capacity

Firewall Throughput

IDP Throughput

Default

1,000,000

256,000

10 Gbps

2.4 Gbps

Equal

1,000,000

1,000,000

8.5 Gbps

2 Gbps

Firewall

1,000,000

1,000,000

10 Gbps

2.4 Gbps

IDP

1,000,000

1,000,000

5.5 Gbps

1.4 Gbps

Usage Guidelines

For configuration instructions and examples, see the Junos OS Security Configuration Guide.

Required Privilege Level

security—To view this statement in the configuration.

security-control—To add this statement to the configuration.