Description

In May of 2014, Juniper introduced new IDP policy templates  for better coverage. Customers need to consider which policy would be best for them and tweak the policies as needed, especially on low-end SRXs.


Symptoms

Constant high CPU has been seen on SRXs since the new IDP policy templates were introduced.


Solution

Please be aware that the old recommended policy contains only client-to-server attacks, in other words, server protection only and not client protection. This is documented in the standalone IDP documentation for IDP 5.1 on page 109, Table 21, "Recommended Security Policy Definition," in the IDP Series Concepts and Examples Guide, Page 109, Table 21 .

The new Client and Server Protection IDP policy template contains BOTH client-to-server (server protection) as well as server-to-client attacks (client protection). High CPU with the Client and Server Protection IDP policy template can be expected depending on how much server-to-client traffic is present on the network. In general, server-to-client signatures consume more CPU.

The analogous policy for the Recommended policy in new templates is Server Protection, so customers who wish to transition from Recommended to new policy templates should use Server Protection if they are looking for the equivalent of a Recommended policy.

If customers wish to use a Client and Server Protection policy on low-end devices with 2 GB of memory, the policy needs to be tweaked, for example, by removing the Info, Warning, and Minor attack signatures while accordingly keeping CPU consumption in mind.