background image

Table 5: Known Issues

(continued)

Description

PR

CPU Utilization

In the

NSM Device Monitor > View Device Details > Process Status

tab, the CPU usage for the IDP engine is

reported as 0%. To see the actual CPU usage for an IDP engine, log into the IDP Series device command-line
interface (CLI) and use the

scio idp-cpu-utilization

command (multicore platforms) or Linux

top

command

(single-core platforms). The correct CPU usage is also reported via SNMP.

434539

Stability

IDP8200 stops processing traffic at high load with SYN protection enabled.

430363

For single core platforms (IDP75, IDP200, IDP600), we recommend you disable application volume tracking
(AVT). AVT processes are CPU intensive, resulting in link flapping under stress.

Note that if you disable AVT, IDP Reporter application volume reports are empty.

499447

Low memory triggered JNET bypass on IDP800.

573031

Expected Behavior

Packet drops are possible in simulation mode if the JNET free packet buffer is 0.

547354

Shutdown Operation

The

shutdown -h now

command might not behave as expected if you deploy IDP8200 with any of the following

fiber I/O modules: IDP-1GE-4SX-BYP, IDP-10GE-2XFP, or IDP-10GE-2SR-BYP. Instead of shutting down, the
OS unexpectedly restarts. This issue has been reported only in the initial shipments of this hardware. For details
and a solution, contact JTAC.

432893

Documentation

In NSM Device Manager, a new configuration section for Report Settings does not include online help. For
information about the report settings you can configure with NSM, see the

“IDP Logs and Reports in NSM

Task Summary”

section in the

IDP Series Administration Guide

.

424045

Documentation

You can download user documentation from the Juniper Networks Web site:

http://www.juniper.net/techpubs/

.

Table 6 on page 20 lists related IDP Series documentation.

Table 6: Related IDP Series Documentation

Description

Document

Provides information about IDP Detector Engine releases, including new
features, changed features, fixed problems, and known issues.

IDP Detector Engine release notes

Copyright © 2011, Juniper Networks, Inc.

20

Juniper Networks Intrusion Detection and Prevention Release Notes

Содержание IDP OS 5.1R1

Страница 1: ...4 Supported Upgrade Paths 5 Downgrading or Reverting 6 Licensing 6 Compatibility with Network and Security Manager 6 Compatibility with Juniper Networks Infranet Controller 7 Browser Requirements 7 Up...

Страница 2: ...r from the primary path to the backup path in cases of failure For details see IDP Series Deployment Scenarios High availability Beginning in IDP OS Release 5 1 you can operate the IDP Series device i...

Страница 3: ...ication Beginning with IDP OS Release 5 1 You can create rules that match extended application objects also called nested application objects You can apply a new action to matching rules DiffServ Rate...

Страница 4: ...0 10 gigabyte fiber interfaces do not support interface signaling or peer port modulation Also not supported in IDP OS Release 5 0 x Authentication to the ACM via RADIUS with RSA SecurID authenticatio...

Страница 5: ...hanges to files and directories you will notice when you upgrade Table 2 Changes to Files and Directories Files and Directories Upgrade Path No changes to attend to before upgrade From 5 0r2 Before yo...

Страница 6: ...s no longer supported in IDP 5 1 The upgrade process saves a backup of your previous usr idp device bin user_funcs file but installs a new user_funcs file in order to provide appropriate content for I...

Страница 7: ...Start utility and IDP Reporter have been tested on the following browsers Internet Explorer 7 x 6 x Firefox 3 x 2 x Upgrading IDP Software During upgrade the IDP Series appliance is gracefully shut do...

Страница 8: ...password b Enter the IDP Series device serial number to display a view of applicable software releases available for download c Click the applicable link to display the software download page d Downlo...

Страница 9: ...the BIOS setting Console redirection Continue Console redirection after POST to ON To resolve this issue press the Delete key to enter BIOS and set this option to OFF Next Steps If you are upgrading...

Страница 10: ...vailable for download c Click the applicable link to display the software download page d Save the sensor_version sh file where version is the number that identifies the software release version 2 Con...

Страница 11: ...r2 skip this step You completed it when you upgraded to IDP 5 0 If you are upgrading from IDP OS Release 4 1r4 1 a Run through the ACM wizard to reconfigure your virtual routers In IDP 5 0 and later y...

Страница 12: ...O modules 308133 Unexpected Behavior Resolved an issue where the SYN Protector rulebase had failed to reset the destination server connections when configured in Passive mode 417818 Resolved an issue...

Страница 13: ...s reached In this release we have changed the delay threshold from 1024 to 100 instances 388321 Syslog NIC state events reported in syslog messages had not indicated that the virtual router has return...

Страница 14: ...ith APE rules would eventually result in policy push errors 494931 Resolved an issue where running sciocpu utilization command in single core platforms caused a drop in throughput and increase in late...

Страница 15: ...uters page should not display the user interface group for NIC State When no installed I O module supports bypass NIC state is non configurable 286327 ACM does not reject poorly formed alias names In...

Страница 16: ...uplex settings match We have observed traffic dropping if the IDP Series interfaces are configured as 100 10 1000 half full duplex AUTO OFF and the peer switch or firewall is configured as AUTO ON 431...

Страница 17: ...ata1 00 cmd 61 30 08 8d 6e 16 00 00 00 00 00 40 tag 1 cdb 0x0 data 24576 out res 50 00 38 a5 70 16 00 00 00 00 00 40 Emask 0x2 HSM violation You can safely ignore these messages 288824 During upgrade...

Страница 18: ...ted in syslog messages do not indicate which IDP engine restarted 427100 Database limit exceeded alert log are not displayed in Profiler logs 429086 We have observed a minor loss of application volume...

Страница 19: ...3 rxBytes 14757418499789 rxOverflow 0 rxQueued 0 txComplete 18487802326 txCompleteBytes 14691015670286 allocQueueSize 1023 txPackets 18487802326 txBytes 14692307273740 Device Id 0 eth2 Stats Link Stat...

Страница 20: ...hutdown Operation The shutdown h now command might not behave as expected if you deploy IDP8200 with any of the following fiber I O modules IDP 1GE 4SX BYP IDP 10GE 2XFP or IDP 10GE 2SR BYP Instead of...

Страница 21: ...scribes how to use IDP Reporter an on box reporting platform that includes predefined reports on attack detection and application usage You can also use IDP Reporter to schedule regular publication of...

Страница 22: ...act Juniper Networks Technical Assistance Center JTAC by E mail support juniper net or telephone 1 888 314 JTAC within the United States or 1 408 745 9500 from outside the United States Copyright 2009...

Отзывы: