Table 5: Known Issues
(continued)
Description
PR
CPU Utilization
In the
NSM Device Monitor > View Device Details > Process Status
tab, the CPU usage for the IDP engine is
reported as 0%. To see the actual CPU usage for an IDP engine, log into the IDP Series device command-line
interface (CLI) and use the
scio idp-cpu-utilization
command (multicore platforms) or Linux
top
command
(single-core platforms). The correct CPU usage is also reported via SNMP.
434539
Stability
IDP8200 stops processing traffic at high load with SYN protection enabled.
430363
For single core platforms (IDP75, IDP200, IDP600), we recommend you disable application volume tracking
(AVT). AVT processes are CPU intensive, resulting in link flapping under stress.
Note that if you disable AVT, IDP Reporter application volume reports are empty.
499447
Low memory triggered JNET bypass on IDP800.
573031
Expected Behavior
Packet drops are possible in simulation mode if the JNET free packet buffer is 0.
547354
Shutdown Operation
The
shutdown -h now
command might not behave as expected if you deploy IDP8200 with any of the following
fiber I/O modules: IDP-1GE-4SX-BYP, IDP-10GE-2XFP, or IDP-10GE-2SR-BYP. Instead of shutting down, the
OS unexpectedly restarts. This issue has been reported only in the initial shipments of this hardware. For details
and a solution, contact JTAC.
432893
Documentation
In NSM Device Manager, a new configuration section for Report Settings does not include online help. For
information about the report settings you can configure with NSM, see the
“IDP Logs and Reports in NSM
Task Summary”
section in the
IDP Series Administration Guide
.
424045
Documentation
You can download user documentation from the Juniper Networks Web site:
http://www.juniper.net/techpubs/
.
Table 6 on page 20 lists related IDP Series documentation.
Table 6: Related IDP Series Documentation
Description
Document
Provides information about IDP Detector Engine releases, including new
features, changed features, fixed problems, and known issues.
IDP Detector Engine release notes
Copyright © 2011, Juniper Networks, Inc.
20
Juniper Networks Intrusion Detection and Prevention Release Notes