I have a VSX cluster running on open-software on 12 core 256GB RAM HP DL380p Gen 8 boxes.
The cluster has Just 3 virtual Firewalls on it.
2 of these VS's have no problems what so ever, one of them has 10K+ connections 24 hours a day.
my 3rd which has maybe 25 to 30 workstations behind it with one average less that 1000 concurrent connections keeps having problems.
About every 9 days or so, user behind the firewall complain the network is slow.
I've put a ping and jitter monitor on one of the networks behind the firewall to monitor.
All of a sudden ping times and Jitter start to rise over a period of an hour the ping times to a device on the other side of the firewall ( it's an internal firewall) rise from <1ms to between 800ms - 1000ms
the only fix I've found to bring the ping times down is the "vsx_util vsls" and move the VS's all to the other node of the affected firewall ping times drop and I can redistribute the load again.
I have tried leaving it on the single node but ping times still rise.
I have even rebuilt the VS from scratch and it when 20 days before we had the incident again.
Support have not found an answer yet ( it's been several months so far.)
has anyone come across this or have any ideas?
Blades running on the VS are
Firewall
IPS
Identity Awareness
Url Filtering
Application Control
The cluster is running R77.20 no hot fixes.
CoreXL is on.
So whats been done.
Cluster was upgraded from R77 to R77.20
CoreXL for some reason was not on, has been turned on.
VS having the problem has been removed and rebuilt from scratch.
This morning after having the issue recurred over the weekend during the early morning when there was little traffic through the firewall I’ve change the IPS profile for my custom profile to the default profile to see if that helps.
Bookmarks