Configure elephant flow parameters

Configure elephant flow detection and remediation settings to identify high-bandwidth connections, and manage them through bypassing or throttling to maintain optimal system performance during high CPU utilization.

Elephant flows are high-bandwidth, long-duration connections that can impact system performance. By configuring elephant flow parameters, you can detect these flows and apply appropriate remediation actions such as bypassing trusted applications from inspection or throttling flows that cause system duress.

Procedure


Step 1

Choose Policies > Security policies > Access Control.

Step 2

Click Edit (edit icon) next to the access control policy that you want to edit.

Step 3

Choose Advanced Settings from the More drop-down arrow at the end of the packet flow line.

Step 4

Click Edit (edit icon) next to Elephant Flow Settings.

The diagram illustrates the configuration parameters for elephant flow management in a network, highlighting key settings and their impact on traffic handling.

Step 5

The Elephant Flow Detection toggle button is enabled by default. The default setting enables detection only and no default action is configured. The detection settings allow you to adjust the flow bytes and duration so that you can identify the elephant flows in your system.

As a test setting, configure the flow bytes and duration parameters, as shown in the following figure.

The figure illustrates the configuration settings for elephant flow parameters, including flow bytes and duration, in a network management interface.

Step 6

Enable the Elephant Flow Remediation toggle button. When an elephant flow is detected, you can choose to bypass or throttle the flow. Bypassing a flow means that the traffic is allowed to pass without Snort inspection. Throttling indicates that the flow throughput is reduced. This rate reduction is done in 10 percent increments until the CPU utilization decreases to less than the configured threshold.

As a test setting, configure the elephant flow remediation parameters as shown in the following figure.

The figure illustrates the configuration settings for elephant flow remediation parameters in a network environment. It provides a visual reference for the specific values and options to be set during the configuration process.

Step 7

Enable the Bypass the flow toggle button and click the Select Applications/Filters radio button.

The diagram illustrates the configuration parameters for elephant flow management in a network, highlighting key settings and their impact on performance.

Step 8

Under Application Filters, search for and select the WebEx application, add it to the rule, and click Save. This means that WebEx connections are trusted and prioritized. These connections will skip Snort inspection if detected as elephant flows based on the configured parameters.

The diagram illustrates the configuration parameters for elephant flow management, highlighting key settings and their impact on network performance.

Step 9

Enable the Throttle toggle button to throttle the remaining flows (causing duress). This ensures that all the other flows are slowed down in 10 percent increments until the Snort duress condition is met.

Click OK and then Save.


What to do next

Deploy configuration changes. Refer to Deploy configuration changes.