iptables performance causing Apache webserver lockup
Hi
Our Apache2 server (2.4.16 MPM-prefork) is sporadically entering a state where all connections are taken up showing "W - sending reply" in the server status monitor.
The server is running on a Xen VM with three dedicated CPUs and 14GB of memory.
I understand that the above issue can be caused by multiple root causes, notably poor scripts or a slow MySql connection.
I have spent days optimizing and debugging using strace, etc.
Finally, it seems that the issue isolates to degraded firewall performance. A firewall restart restores performance until degradation occurs again in the future.
Our firewall is running Debian 3.14-2-rt-686-pae with iptables 1.4.21
It performs filtering and NAT for our network. There are 8 uusers on the network with limited internet usage.
The firewall runs on a dedicated server with four Intel Xeon CPUs (3.06GHz) and 4GB of memory. The firewall also runs Squid/Icap proxy server and Snort.
Any ideas?
|