This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IIS Performance Issues

We are having performance issues with SafeGuard 5.5 client’’’’s sync'ing with the management servers whereby it takes an extraordinarily long time for them to properly register and receive the appropriate certificates and keys.

From looking at the management servers this issue would appear to be with the performance of the IIS servers; the w3wp.exe process consumes 100% of CPU time (of a single core) and the processes keep being recycled due to the following:

Event Type: Information

Event Source: W3SVC

Event Category: None

Event ID: 1077

Date: 14/09/2012

Time: 10:17:07

User: N/A

Computer: <server>

Description:

A worker process with process id of '5092' serving application pool 'SGNSRV-Pool' has requested a recycle because it reached its virtual memory limit.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Has anyone experienced this issue and can offer some help to resolve the problem?

Cheers,

James

System details:

Management Servers

SafeGuard Enterprise 5.50.8.13 Server

SafeGuard 5.50.8.13 Management Server

SafeGuard Enterprise 5.50.8.13 Web Helpdesk

Windows Server 2003 R2 SP2

4GB, 4 x vCPU

SQL Server

SQL Server 2008 R2

Windows Server 2008 R2 Standard SP1

8GB, 4 x CPU

:29561


This thread was automatically locked due to age.
Parents
  • Hi JPSealey,

    as you've already mentioned, a major IIS performance improvement can be achieved when switching to SSL encryption. Setting up SSL between Client and Server is described in the SafeGuard Enterprise Installation Best Practice Guide (sgn_60_bpg_eng_installation_best_practice.pdf) - Chapter 5. "Configuring the SGNSRV web page to accept a certificate and assigning the certificate".

    Nevertheless, 10 clients should not bring a SGNServer to 100% CPU load. From my personal experience, I'd recommend to check the following things first:

    - SafeGuard Enterprise Client-Server Connection interval: Check the currently configured interval in the SafeGuard Enterprise policy and increase the interval time if required (4h is recommendable in most of the cases - you have to consider that clients also connect the server after startup)

    - Try to avoid "Administrative POA Groups" where a big amount of users is assigned to every SafeGuard Client to give administrative staff POA access. Use the "POA Groups" feature instead.

    In case above should not help out, I'd recommend to open up a support request and have support check the situation.

    One more thing as you're running an older release of SafeGuard Enterprise; are all SafeGuard services on the server machine in the "running" state or is any one those stopped or "starting"/"stopping"? How many files are located in the following folders

    - C:\ProgramData\Utimaco\SafeGuard Enterprise\LocalCache\auditing

    - C:\ProgramData\Utimaco\SafeGuard Enterprise\LocalCache\transout

    Regards,

    Chris

    :31263
Reply
  • Hi JPSealey,

    as you've already mentioned, a major IIS performance improvement can be achieved when switching to SSL encryption. Setting up SSL between Client and Server is described in the SafeGuard Enterprise Installation Best Practice Guide (sgn_60_bpg_eng_installation_best_practice.pdf) - Chapter 5. "Configuring the SGNSRV web page to accept a certificate and assigning the certificate".

    Nevertheless, 10 clients should not bring a SGNServer to 100% CPU load. From my personal experience, I'd recommend to check the following things first:

    - SafeGuard Enterprise Client-Server Connection interval: Check the currently configured interval in the SafeGuard Enterprise policy and increase the interval time if required (4h is recommendable in most of the cases - you have to consider that clients also connect the server after startup)

    - Try to avoid "Administrative POA Groups" where a big amount of users is assigned to every SafeGuard Client to give administrative staff POA access. Use the "POA Groups" feature instead.

    In case above should not help out, I'd recommend to open up a support request and have support check the situation.

    One more thing as you're running an older release of SafeGuard Enterprise; are all SafeGuard services on the server machine in the "running" state or is any one those stopped or "starting"/"stopping"? How many files are located in the following folders

    - C:\ProgramData\Utimaco\SafeGuard Enterprise\LocalCache\auditing

    - C:\ProgramData\Utimaco\SafeGuard Enterprise\LocalCache\transout

    Regards,

    Chris

    :31263
Children
No Data