среда, 8 февраля 2017 г.

Juniper MX CG-NAT based on MS-MIC capacity and performance examples from production

Здесь собраны реальные примеры использования CG-NAT на оборудовании Juniper MX5-80/104. Данные значения являются демонстрационными и представлены исключительно для сравнения и общего понимания возможностей MS-MIC.

Here you can find actual examples of the use of CG-NAT on Juniper MX5-80 / 104 hardware. These values are for demonstration and presented exclusively for comparison and a common understanding of MS-MIC opportunities.


Let's start...


1. MX80, 5k DHCP clients, 80k NAT service sessions.
NAT-ing by firewall filter on demux interface.

~1.5 Gbps
~ 80k NAT sessions

Junos: 14.2R7.5

am@client1> show services sessions count
Interface   Service set                                          Sessions count
ms-0/2/0    NAT                                                           68998

am@client1> show services service-sets summary
             Service sets                                           CPU
Interface    configured             Bytes used   Policy bytes used  utilization
ms-0/2/0           2  1477755908      (12.80%)    3265344 ( 0.30%)  10.86 %

am@client1> show interfaces ms-0/2/0
Physical interface: ms-0/2/0, Enabled, Physical link is Up
  Interface index: 167, SNMP ifIndex: 2651
  Type: Adaptive-Services, Link-level type: Adaptive-Services, MTU: 9192, Speed: 20000mbps
  Device flags   : Present Running
  Interface flags: Point-To-Point SNMP-Traps
  Link type      : Full-Duplex
  Link flags     : None
  Last flapped   : 2017-01-28 18:11:31 EET (1w3d 19:34 ago)
  Input rate     : 1331461296 bps (182346 pps)
  Output rate    : 1332709176 bps (184574 pps)

2. MX104, 10.5k DHCP clients, 1.2M NAT service sessions.
NAT-ing by firewall filter on demux interface.

~6.5 Gbps
~ 1.2M NAT sessions

Junos: 13.3R8.7

am@client2> show services sessions count
Interface   Service set                                          Sessions count
ms-1/2/0    NAT-SET                                                     1087316

am@client2> show services service-sets summary
             Service sets                                           CPU
Interface    configured             Bytes used   Policy bytes used  utilization
ms-1/2/0           2  1826857604      (42949672.96%)    6622112 ( 1.23%)  56.87 %

am@client2> show interfaces ms-1/2/0
Physical interface: ms-1/2/0, Enabled, Physical link is Up
  Interface index: 170, SNMP ifIndex: 15956
  Type: Adaptive-Services, Link-level type: Adaptive-Services, MTU: 9192, Speed: 20000mbps
  Device flags   : Present Running
  Interface flags: Point-To-Point SNMP-Traps
  Link type      : Full-Duplex
  Link flags     : None
  Last flapped   : 2016-10-30 13:02:14 EET (14w3d 01:17 ago)
  Input rate     : 6076502384 bps (825002 pps)
  Output rate    : 6079938544 bps (833270 pps)

3. MX104, Redundant MS-MIC + load balancing, 7k DHCP clients, 300k NAT service sessions.
NAT-ing by forwarding-options filter (FBF).

~5.0 Gbps
~ 400k NAT sessions

Junos: 15.1R5.5

am@client3> show services sessions count
Interface   Service set                                          Sessions count
mams-0/2/0  NAT-SERVICE-SET                                              151384
mams-1/0/0  NAT-SERVICE-SET                                              132472

am@client3> show services service-sets summary
             Service sets                                           CPU
Interface    configured             Bytes used   Policy bytes used  utilization
ms-0/2/0           2  1615511781      (13.99%)    8030776 ( 0.74%)  18.00 %
ms-1/0/0           2  1589612549      (13.77%)    8021712 ( 0.74%)  16.63 %

am@client3> show interfaces ams0
Physical interface: ams0, Enabled, Physical link is Up
  Interface index: 179, SNMP ifIndex: 551
  Type: Adaptive-Services, Link-level type: Adaptive-Services, MTU: 9192, Speed: 40000mbps
  Device flags   : Present Running
  Interface flags: Point-To-Point SNMP-Traps Internal: 0x0
  Link type      : Full-Duplex
  Link flags     : None
  Last flapped   : 2017-01-17 14:27:51 EET (3w0d 23:57 ago)
  Input rate     : 4075308504 bps (572676 pps)
  Output rate    : 4121909608 bps (575395 pps)

4. MX80, 3.2k DHCP, 1.5k PPPoE, 700k NAT service sessions.
NAT-ing by firewall filter on demux interface.

~3.0 Gbps
~ 700k NAT sessions

am@client4> show services sessions count
Interface   Service set                                          Sessions count
ms-0/2/0    NAT-SERVICE-SET                                              553742

am@client4> show services service-sets summary
             Service sets                                           CPU
Interface    configured             Bytes used   Policy bytes used  utilization
ms-0/2/0           2  1335264160      (11.05%)   23019912 ( 4.28%)  15.19 %

am@client4> show interfaces ms-0/2/0
Physical interface: ms-0/2/0, Enabled, Physical link is Up
  Interface index: 164, SNMP ifIndex: 3126
  Type: Adaptive-Services, Link-level type: Adaptive-Services, MTU: 1518, Speed: 20000mbps
  Device flags   : Present Running
  Interface flags: Point-To-Point SNMP-Traps
  Link type      : Full-Duplex
  Link flags     : None
  Last flapped   : 2017-01-27 15:20:14 EET (1w4d 23:23 ago)
  Input rate     : 2343420784 bps (326115 pps)
  Output rate    : 2345558528 bps (329533 pps)

5. MX5, 5.5k DHCP clients, 350k NAT service sessions.
NAT-ing by forwarding-options filter (FBF).

~5.0 Gbps
~ 350k NAT sessions

Junos: 13.3R9.13

am@client5> show services sessions count
Interface   Service set                                          Sessions count
ms-0/2/0    NAT-SERVICE-SET                                              269178

am@client5> show services service-sets summary
             Service sets                                           CPU
Interface    configured             Bytes used   Policy bytes used  utilization
ms-0/2/0           2  1093822400      ( 9.05%)    8012128 ( 1.49%)  96.82 % OVLD

am@client5> show interfaces ms-0/2/0
Physical interface: ms-0/2/0, Enabled, Physical link is Up
  Interface index: 169, SNMP ifIndex: 521
  Type: Adaptive-Services, Link-level type: Adaptive-Services, MTU: 9192, Speed: 20000mbps
  Device flags   : Present Running
  Interface flags: Point-To-Point SNMP-Traps
  Link type      : Full-Duplex
  Link flags     : None
  Last flapped   : 2016-11-30 04:34:39 EET (10w0d 10:10 ago)
  Input rate     : 5564293648 bps (2920752 pps)
  Output rate    : 5566079376 bps (2922785 pps)

Комментариев нет:

Отправить комментарий