Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

VPN session affinity

More Information:

VPN session affinity

VPN session affinity occurs when a clear-text session is located in a Services Processing Unit (SPU) that is different from the SPU where the IPsec tunnel session is located. The goal of VPN session affinity is to locate the clear-text and IPsec tunnel session in the same SPU. Without VPN session affinity, a clear-text session created by a flow might be located in one SPU and the tunnel session created by IPsec might be located in another SPU. An SPU to SPU forward or hop is needed to route clear-text packets to the IPsec tunnel. By default, VPN session affinity is disabled on SRX Series devices. Enabling VPN session affinity can improve VPN throughput under certain conditions.
Product / Application Software Introduced Release
SRX5400 Junos OS 15.1X49-D10
SRX5400 Junos OS 12.3X48-D30
SRX5400 Junos OS 12.1X46-D10
SRX5600 Junos OS 15.1X49-D10
SRX5600 Junos OS 12.3X48-D30
SRX5600 Junos OS 11.4R5
SRX5800 Junos OS 15.1X49-D10
SRX5800 Junos OS 12.3X48-D30
SRX5800 Junos OS 11.4R5