[125595] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Juniper firewalls - SSG or SRX

daemon@ATHENA.MIT.EDU (Richard A Steenbergen)
Tue Apr 20 08:01:53 2010

Date: Tue, 20 Apr 2010 07:01:31 -0500
From: Richard A Steenbergen <ras@e-gerbil.net>
To: Owen DeLong <owen@delong.com>
In-Reply-To: <81231BA3-AB5C-4ADF-83C8-DAC7BB097463@delong.com>
Cc: nanog@nanog.org, Cian Brennan <cian.brennan@redbrick.dcu.ie>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

On Tue, Apr 20, 2010 at 04:18:11AM -0700, Owen DeLong wrote:
> 
> Interesting. My SRXes have been rock solid since upgrading to
> 10.0R1.8.

Not so much here. My basement SRX210 starts dropping bgp sessions over
an IPSEC tunnel every 30 secs or so after around 1-1.5 days of uptime,
and won't stop until you restart rpd (which buys you another day or so
of functioning bgp). And about 1 out of every 4 times you do restart
rpd, dhcpd will spin at 100% cpu until you restart that too. Even
10.1S1.3 doesn't help these issues. It's a nice box in theory, and it
has lots of potential, but lots and lots of unresolved bugs too. I knew
things were off to a bad start when I tried to downgrade from the 10.0R1
that shipped with the box to 9.6 after my first round of issues, and it
crashed in the middle of the installer, wiping the config in the process
and requiring a tftp boot of new code to recover. :)

-- 
Richard A Steenbergen <ras@e-gerbil.net>       http://www.e-gerbil.net/ras
GPG Key ID: 0xF8B12CBC (7535 7F59 8204 ED1F CC1C 53AF 4C41 5ECA F8B1 2CBC)


home help back first fref pref prev next nref lref last post