LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-01-2015, 12:37 AM   #1
LastBoyScout
LQ Newbie
 
Registered: Sep 2015
Posts: 2

Rep: Reputation: Disabled
iptables performance causing Apache webserver lockup


Hi

Our Apache2 server (2.4.16 MPM-prefork) is sporadically entering a state where all connections are taken up showing "W - sending reply" in the server status monitor.

The server is running on a Xen VM with three dedicated CPUs and 14GB of memory.

I understand that the above issue can be caused by multiple root causes, notably poor scripts or a slow MySql connection.

I have spent days optimizing and debugging using strace, etc.

Finally, it seems that the issue isolates to degraded firewall performance. A firewall restart restores performance until degradation occurs again in the future.

Our firewall is running Debian 3.14-2-rt-686-pae with iptables 1.4.21

It performs filtering and NAT for our network. There are 8 uusers on the network with limited internet usage.

The firewall runs on a dedicated server with four Intel Xeon CPUs (3.06GHz) and 4GB of memory. The firewall also runs Squid/Icap proxy server and Snort.

Any ideas?
 
Old 09-01-2015, 11:58 AM   #2
lazydog
Senior Member
 
Registered: Dec 2003
Location: The Key Stone State
Distribution: CentOS Sabayon and now Gentoo
Posts: 1,249
Blog Entries: 3

Rep: Reputation: 194Reputation: 194
This is a very open ended question. It is kind of hard to say what part of your firewall might be causing issues without know how or what rules you are implying on the system. but I'll take a stab at it.

1. What logging are you doing and how much?
2. At what level are you logging if logging is turned on?
3. Are you running a stateful or stateless firewall?
4. How many open tcp connection do you have as failure?
5. Are there many rules making your firewall very complicated?
6. Are you using ipset in conjunction with iptables?
 
Old 09-08-2015, 09:40 AM   #3
LastBoyScout
LQ Newbie
 
Registered: Sep 2015
Posts: 2

Original Poster
Rep: Reputation: Disabled
Thanks

Hi Lazydog

Many thanks for your ideas - I traced some of those through.

Eventually I tracked the problem to a bug in Wordpress that was driving massive creation of wp_crons on every connection. So not networking after all.

Anywaay, with every other thing optimised over the last three weeks, our site is now very speedy!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CSF / LFD causing XENserver Centos VM lockup? kprojects Linux - Software 0 01-27-2012 09:33 PM
slackware 12 fresh install - udev causing lockup on boot l33t_c0w Slackware 13 10-24-2007 01:56 PM
Nvidia drivers causing X lockup? Gato Azul Slackware 14 09-19-2007 07:24 AM
wifi adapters causing kernel lockup dracolich Linux - Laptop and Netbook 2 07-05-2006 04:48 PM
wg511 causing machine lockup d0wn_under Slackware 1 12-29-2004 05:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration