Using Best Practices - Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

174
M
V
ANAGING
IEWS
Step 4
Using Best
Practices
Table 8-23 View Management (continued)
Parameter
Description
Disabled
Using the drop-down list box, select Disabled to disable the view.
This disables the Classification Engine, data collection, data
storage, graphing capabilities, and removes the view from the
interface. To enable access from the interface, select Enabled.
Note: Selecting the Disabled mode can save processing power
on your system.
From the Administration Console menu, select Configurations > Deploy
configuration changes.
Given the complexities and network resources required for STRM in large
structured networks, we recommend the following best practices:
Disable views you are not required to access and display. Disabling views
requires fewer CPU cycles and will not impact processing power in large
structured networks.
Bundle objects and use the Network Surveillance interface to analyze your
network data. Fewer objects create less I/O to your disk.
- Bundled flows include bi-directional traffic with single source and destination
hosts, multiple source and destination ports.
- All original flows are sent but marked as a bundle.
- One Flow Bundle record is sent every interval.
- Classify processes only the bundle and not the flows.
Typically, no more than 200 objects per view (for standard system
requirements). More objects may impact your processing power when
investigating your traffic.
STRM Administration Guide

Advertisement

Table of Contents
loading

Table of Contents