Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-03-01 Thread Youssef Bengelloun-Zahr
Hi, JTAC point me to this PR : https://prsearch.juniper.net/InfoCenter/index?page=prcontent&id=PR1061067 This ressembles a lot to our environment (cluster + LSYS) but we are not affected as we are running 12.3X48-D20. HTH. 2016-02-29 23:35 GMT+01:00 Michael Gehrmann : > Invalidated sessions

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-29 Thread Michael Gehrmann
Invalidated sessions are norma but it's not normal to have an increasing number of invalidated sessions which then prevent the box from passing traffic. This is our experience which has happened twice in 3 months. We saw a ramp up of invalidated sessions which peaked and then stopped all traffic un

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-29 Thread Florian Lohoff
On Mon, Feb 29, 2016 at 04:52:34PM +0100, Youssef Bengelloun-Zahr wrote: > Here is JTAC feedback regarding this : > > "As I have understood it till now, the issue is with the invalidated > sessions seen on the SRX. > > Seeing some number of invalidated sessions on the SRX is a normal behavior. >

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-29 Thread Youssef Bengelloun-Zahr
Here is JTAC feedback regarding this : "As I have understood it till now, the issue is with the invalidated sessions seen on the SRX. Seeing some number of invalidated sessions on the SRX is a normal behavior. Each valid session for which a FIN is received would be moved to the invalidated sessio

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-29 Thread Michael Gehrmann
No but I strongly suggest getting in touch with JTAC and running the debug code. Only way forward at the moment. Mike > On 29 Feb 2016, at 21:32, Youssef Bengelloun-Zahr wrote: > > Hello Michael, > > Any other details you could share regarding affected platforms / junos > versions ? > > BR

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-29 Thread Youssef Bengelloun-Zahr
Hello Michael, Any other details you could share regarding affected platforms / junos versions ? BR. 2016-02-29 7:21 GMT+01:00 Michael Gehrmann : > Nothing public yet. > > > On 29 Feb 2016, at 17:11, Youssef Bengelloun-Zahr wrote: > > Hi, > > So you Have a DEFECT or PR ID for this ? > > BR.

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-28 Thread Florian Lohoff
On Sun, Feb 28, 2016 at 11:35:33PM +0100, Youssef Bengelloun-Zahr wrote: > Hello, > > Could you please both share model and running code versions ? 12.1X44-D35.5 SRX650 After rebooting the affected node the invalidated sessions went and for 48h did not come back. Flo -- Florian Lohoff

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-28 Thread Michael Gehrmann
Nothing public yet. > On 29 Feb 2016, at 17:11, Youssef Bengelloun-Zahr wrote: > > Hi, > > So you Have a DEFECT or PR ID for this ? > > BR. > > > >> Le 28 févr. 2016 à 23:45, Michael Gehrmann a écrit >> : >> >> SRX650 - 12.1X46-D36 >> >> I'm told from JTAC the issue will be present in

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-28 Thread Youssef Bengelloun-Zahr
Hi, So you Have a DEFECT or PR ID for this ? BR. > Le 28 févr. 2016 à 23:45, Michael Gehrmann a écrit : > > SRX650 - 12.1X46-D36 > > I'm told from JTAC the issue will be present in 12.3X48 as no fix has been > identified yet. > > Cheers > Mike > >> On 29 February 2016 at 09:35, Youssef B

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-28 Thread Michael Gehrmann
SRX650 - 12.1X46-D36 I'm told from JTAC the issue will be present in 12.3X48 as no fix has been identified yet. Cheers Mike On 29 February 2016 at 09:35, Youssef Bengelloun-Zahr wrote: > Hello, > > Could you please both share model and running code versions ? > > Best regards. > > > > > Le 28

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-28 Thread Youssef Bengelloun-Zahr
Hello, Could you please both share model and running code versions ? Best regards. > Le 28 févr. 2016 à 23:27, Michael Gehrmann a écrit : > > We have had the same issue on branch series. Juniper is asking us to run a > debug version of code. I suggest you contact JTAC. > > Cheers > Mike >

Re: [j-nsp] Monitor SRX "Invalidated Session"

2016-02-28 Thread Michael Gehrmann
We have had the same issue on branch series. Juniper is asking us to run a debug version of code. I suggest you contact JTAC. Cheers Mike On 28 February 2016 at 23:04, Florian Lohoff wrote: > > Hi, > > We had an incident with one node of an SRX Cluster piling up > invalidated sessions as seen f

[j-nsp] Monitor SRX "Invalidated Session"

2016-02-28 Thread Florian Lohoff
Hi, We had an incident with one node of an SRX Cluster piling up invalidated sessions as seen from "show security session flow summary" Now i was looking for the SNMP Mibs to monitor the number of invalidated sessions per node but failed to find one. JUNIPER-LSYSSP-FLOWSESS-MIB has max/current