This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Proxy Local content filtering database?

Had to turn off the http proxy yet again..come on guys get this feature pushed out or fix your bandwidth issues.


This thread was automatically locked due to age.
Parents
  • ok so the cpu is highly loaded.  afcd is the ips/p2p control otherwise known as snort.  so by your numbers you are using 65 to 95% cpu.  afcd is the snort engine this means you have ips/p2p turned on.  This is highly cpu/ram/bus intensive.  you don't have enough cpu to move 10k users through that box and that's why you can't get the performance you want.  you have a few choices:

    1. reduce the suers on that segment
    2.  get a second 625 and do an active/active cluster
    3.  Build a custom monster box with at least 8 3ghz cores and 16 gigs of ram

    You can try disabling all ids/p2p functions..if that helps then that's a bandaid..but doesn't address the underlying issue..you have too many users on the box.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Also, I believe afcd is single-threaded, so a bigger box may not help.

    Although if it just loses track of packets instead of dropping them, it shouldn't block anything.

    Barry
Reply Children
No Data