Description

SNMP may cause high CPU.

Symptoms

On EX/QFX switches, SNMP & MIB2D processes are high or spiking.

 

SNMP may cause high CPU on switches

 

{master:0}[edit]

user@switch# run show system processes extensive | except 0.00

 

 PID USERNAME PRI NICE  SIZE  RES STATE  TIME  WCPU COMMAND

 1924 root   43  -1 1268M  598M RUN  349.7H 34.62% fxpc

  10 root   155  52   0K  12K RUN  393.7H 31.88% idle

 2152 root    4  0 58444K 44120K pfesta 102.6H 11.87% mib2d

 2153 root    4  0  205M  107M kqread 661:59 3.76% rpd

 2171 root   40  0 37228K 30872K RUN   26.9H 3.08% snmpd

 

 

 

 PID USERNAME PRI NICE  SIZE  RES STATE  TIME  WCPU COMMAND

 1924 root   43  -1 1268M  598M select 349.7H 32.23% fxpc

  10 root   155  52   0K  12K RUN  393.7H 25.54% idle

 2152 root   51  0 58508K 44184K RUN  102.6H 18.07% mib2d

 2171 root   43  0 37228K 30872K RUN   26.9H 5.52% snmpd

 

 

With a monitoring traffic check the traffic going to the routing engine and you could frequent getbulk requests.

 

{master:0}

user@switch> monitor traffic interface <interface name> no-resolve size 1500

verbose output suppressed, use <detail> or <extensive> for full protocol decode

Address resolution is OFF.

Listening on et-0/0/98, capture size 1500 bytes

 

13:06:28.033541 In IP 1.1.1.1.59145 > 2.2.2.2.161: C=ijLbcz8A GetBulk(32) N=0 M=10 .1.3.6.1.2.1.31.1.1.1.3.833

13:06:28.037607 In IP 1.1.1.1.33241 > 2.2.2.2.161: C=ijLbcz8A GetBulk(32) N=0 M=10 .1.3.6.1.2.1.10.7.2.1.3.664

13:06:28.037643 In IP 1.1.1.1.57241 > 2.2.2.2.161: C=ijLbcz8A GetBulk(32) N=0 M=10 .1.3.6.1.2.1.10.7.2.1.3.664

13:06:28.154181 Out IP 2.2.2.2.161 > 1.1.1.1.33241: C=ijLbcz8A GetResponse(205) .1.3.6.1.2.1.10.7.2.1.3.666=0 .1.3.6.1.2.1.10.7.2.1.3.667=0 .1.3.6.1.2.1.10.7.2.1.3.668=0 .1.3.6.1.2.1.10.7.2.1.3.669=0 .1.3.6.1.2.1.10.7.2.1.3.670=0 .1.3.6.1.2.1.10.7.2.1.3.671=0 .1.3.6.1.2.1.10.7.2.1.3.672=0 .1.3.6.1.2.1.10.7.2.1.3.673=0 .1.3.6.1.2.1.10.7.2.1.3.674=0 .1.3.6.1.2.1.10.7.2.1.3.675=0

13:06:28.155276 Out IP 2.2.2.2.161 > 1.1.1.1.57241: C=ijLbcz8A GetResponse(205) .1.3.6.1.2.1.10.7.2.1.3.666=0 .1.3.6.1.2.1.10.7.2.1.3.667=0 .1.3.6.1.2.1.10.7.2.1.3.668=0 .1.3.6.1.2.1.10.7.2.1.3.669=0 .1.3.6.1.2.1.10.7.2.1.3.670=0 .1.3.6.1.2.1.10.7.2.1.3.671=0 .1.3.6.1.2.1.10.7.2.1.3.672=0 .1.3.6.1.2.1.10.7.2.1.3.673=0 .1.3.6.1.2.1.10.7.2.1.3.674=0 .1.3.6.1.2.1.10.7.2.1.3.675=0

13:06:28.158258 Out IP 2.2.2.2.161 > 1.1.1.1.60272: C=ijLbcz8A GetResponse(205) .1.3.6.1.2.1.31.1.1.1.3.834=0 .1.3.6.1.2.1.31.1.1.1.3.835=0 .1.3.6.1.2.1.31.1.1.1.3.836=2 .1.3.6.1.2.1.31.1.1.1.3.837=0 .1.3.6.1.2.1.31.1.1.1.3.838=0 .1.3.6.1.2.1.31.1.1.1.3.839=0 .1.3.6.1.2.1.31.1.1.1.3.840=0 .1.3.6.1.2.1.31.1.1.1.3.841=1 .1.3.6.1.2.1.31.1.1.1.3.842=0 .1.3.6.1.2.1.31.1.1.1.3.843=16

13:06:28.159060 Out IP 2.2.2.2.161 > 1.1.1.1.59145: C=ijLbcz8A GetResponse(205) .1.3.6.1.2.1.31.1.1.1.3.834=0 .1.3.6.1.2.1.31.1.1.1.3.835=0 .1.3.6.1.2.1.31.1.1.1.3.836=2 .1.3.6.1.2.1.31.1.1.1.3.837=0 .1.3.6.1.2.1.31.1.1.1.3.838=0 .1.3.6.1.2.1.31.1.1.1.3.839=0 .1.3.6.1.2.1.31.1.1.1.3.840=0 .1.3.6.1.2.1.31.1.1.1.3.841=1 .1.3.6.1.2.1.31.1.1.1.3.842=0 .1.3.6.1.2.1.31.1.1.1.3.843=16

13:06:28.169554 In IP 1.1.1.1.33241 > 2.2.2.2.161: C=ijLbcz8A GetBulk(32) N=0 M=10 .1.3.6.1.2.1.10.7.2.1.3.675

13:06:28.169640 In IP 1.1.1.1.57241 > 2.2.2.2.161: C=ijLbcz8A GetBulk(32) N=0 M=10 .1.3.6.1.2.1.10.7.2.1.3.675

13:06:28.179510 In IP 1.1.1.1.60272 > 2.2.2.2.161: C=ijLbcz8A GetBulk(32) N=0 M=10 .1.3.6.1.2.1.31.1.1.1.3.843

13:06:28.179546 In IP 1.1.1.1.59145 > 2.2.2.2.161: C=ijLbcz8A GetBulk(32) N=0 M=10 .1.3.6.1.2.1.31.1.1.1.3.843

 

Solution

Frequent polling of a large number of counters, especially statistics, can impact the device. We recommend the following optimization on the SNMP managers:

 

  • Use the row-by-row polling method, not the column-by-column method
  • Reduce the number of variable bindings per PDU
  • Increase timeout values in polling and discovery intervals
  • Reduce the incoming packet rate at the SNMP process (snmpd)

 

The following commands can be applied on the switch as well to mitigate a lot of processing.

 

set snmp filter-duplicates

set snmp stats-cache-lifetime <seconds>

 

Modification History

2023/09/15 -Creation date