Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

IDP Performance and Capacity Tuning

This topic provides an overview on performance and capacity tuning for an Intrusion Detection and Prevention (IDP) session.

For more information, see the following topics:

Performance and Capacity Tuning for IDP Overview

This topic provides an overview on performance and capacity tuning for an Intrusion Detection and Prevention (IDP) session.

If you are deploying IDP policies, you can configure the device to increase IDP session capacity. By using the provided commands to change the way the system allocates resources, you can achieve higher IDP session capacity.

By using the maximize-idp-sessions command, you can increase the IDP session capacity. In this mode, by default, the device assigns a greater weight value to firewall functions. Based on your IDP policy, you can shift the weight to IDP functions to maximize IDP performance. By shifting weight, you are increasing capacity and allocating more processing power for the given service.

Note:

You should not configure the device to increase IDP session capacity if you are not using an IDP policy.

The device ships with an implicit default session capacity setting. This default value adds weight to firewall sessions. You can manually override the default by adding the maximize-idp-sessions setting to your configuration. When you do this, in addition to IDP session scaling, you can choose to assign weight values of equal, firewall, or IDP to firewall and IDP functions. Typically, when you only include IDP-recommended attacks or client-to-server attacks in your IDP policy, IDP functions consume less CPU resources, for this reason, you would select weight firewall to maximize device performance. Alternatively, if you add server-to-client attacks to your IDP policy, IDP functions consume higher CPU resources. For this reason, you would select weight IDP to maximize performance. Essentially, you will need to configure the weight based on the desired IDP policy and performance. You do this by examining the CPU resource utilization on the packet forwarding engine by using the show security monitoring fpc number command.

Configuring Session Capacity for IDP (CLI Procedure)

The configuration instructions in this topic describe how modify session capacity for IDP policies.

You do this by adding the maximize-idp-sessions command and then adding the weight option to specify IDP sessions.

Note:

The weight option depends on the maximize-idp-sessions command being set.

  1. If you have an active IDP policy, you can configure the device to increase IDP session capacity by entering following command:
  2. You can further adjust the weight of the firewall and IDP processing functions, such as in the case of heavier IDP policies with the following command:.
  3. Commit your changes. You must reboot the device for any session capacity setting changes to take effect.
    Note:

    If the device has maximize-idp-sessions weight enabled for IDP, and you do not have an IDP policy configured, a warning message appears when you commit your configuration. If you see this warning, you should remove your configured settings.

To turn maximize-idp-sessions settings off, remove the maximize-idp-sessions configuration.

Note:

You must reboot the device for any maximize-idp-sessions setting changes to take effect.