Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

weight (Security)

Syntax

Hierarchy Level

Description

If you are deploying IDP policies, you can tune the device to increase IDP session capacity. By using the provided commands to change the way the system allocates resources, you can achieve a higher IDP session capacity.

Devices ship with an implicit default session capacity setting. This default value gives more weight to firewall sessions. You can manually override the default by using the maximize-idp-sessions command. The command allows you to choose between these weight values: equal, firewall, and idp. The following table displays the available session capacity weight and approximate throughput for each.

Table 1: Session Capacity and Resulting Throughput

Weight Value

Firewall Capacity

IDP Capacity

Firewall Throughput

IDP Throughput

Default

1,000,000

256,000

10 Gbps

2.4 Gbps

equal

1,000,000

1,000,000

8.5 Gbps

2 Gbps

firewall

1,000,000

1,000,000

10 Gbps

2.4 Gbps

idp

1,000,000

1,000,000

5.5 Gbps

1.4 Gbps

This statement is supported on SRX1500, SRX 5800, SRX 5600, and SRX 5400 devices and vSRX Virtual Firewall.

Required Privilege Level

security—To view this in the configuration.

security-control—To add this to the configuration.

Release Information

Statement introduced in Junos OS Release 9.6.