This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Proxy Local content filtering database?

Had to turn off the http proxy yet again..come on guys get this feature pushed out or fix your bandwidth issues.


This thread was automatically locked due to age.
  • After resetting Astaro to its default configs and executing the commands I had these in the HTTP log:

    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_loop" file="epoll.c" line="626" message="starting exit cleanup" 
     httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="scan_exit" file="scanner.c" line="375" message="scanner subsystem shutting down"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="scan_exit" file="scanner.c" line="381" message="scanner subsystem shut down"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_exit" file="epoll.c" line="98" message="epoll subsystem shutting down"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_exit" file="epoll.c" line="108" message="epoll subsystem shut down"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="disk_cache_exit" file="diskcache.c" line="42" message="writing cache index"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="disk_cache_exit" file="diskcache.c" line="44" message="writing cache index done"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="244" message="shutdown finished, exiting"
    Testing httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="174" message="reading configuration"
    Testing httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="189" message="reading profiles"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_load_list" file="scr_scanner.c" line="1123" message="sc type: 2"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_load_list" file="scr_scanner.c" line="1137" message="failed to load list"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_update" file="scr_scanner.c" line="1214" message="started update thread"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_log" file="scr_scanner.c" line="1114" message="Response status was 400 (Bad Request) instead of 200"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_log" file="scr_scanner.c" line="1114" message="The download function returned a permanent error"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_update_list" file="scr_scanner.c" line="1190" message="failed to download list: 41, status 6"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_update_list" file="scr_scanner.c" line="1195" message="serial: SFLX-NSEU-6WFT-2880, perm serial: SFLX-NSEU-6WFT-2880"
  • I just got a chance to test this at home and all I can say is Damn! [:D] I'm running in mem mode on my Atom D510 w/ 4GB RAM and it barely made a dent (21% to 29%) in my memory usage. 

    Transparent mode Content Filtering was (literally) nonfunctional for me prior to this tweak. Now the pages load with just the tinniest little lag vs turning the filters off. If you weren't looking for the lag you probably wouldn't see it.

    Now to wait for 8.2 so I can enable this in production...
  • When updates are applied to the local database, will there be any interruptions to the categorization? We used to use Novell's Bordermanager with SurfControl, and every day it would download updates, and while it was replacing or "patching" the database, all content filtering would fail; I'd hate to see that again, especially if this checks every few minutes. ;-)
  • When updates are applied to the local database, will there be any interruptions to the categorization? We used to use Novell's Bordermanager with SurfControl, and every day it would download updates, and while it was replacing or "patching" the database, all content filtering would fail; I'd hate to see that again, especially if this checks every few minutes. ;-)


    i've been running this for days now and the client i have it on has NOT seen any interruptions.  I would have heard about it if there where..[:)]

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • After resetting Astaro to its default configs and executing the commands I had these in the HTTP log:

    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_loop" file="epoll.c" line="626" message="starting exit cleanup" 
     httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="scan_exit" file="scanner.c" line="375" message="scanner subsystem shutting down"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="scan_exit" file="scanner.c" line="381" message="scanner subsystem shut down"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_exit" file="epoll.c" line="98" message="epoll subsystem shutting down"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="epoll_exit" file="epoll.c" line="108" message="epoll subsystem shut down"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="disk_cache_exit" file="diskcache.c" line="42" message="writing cache index"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="disk_cache_exit" file="diskcache.c" line="44" message="writing cache index done"
    httpproxy[8561]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="244" message="shutdown finished, exiting"
    Testing httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="174" message="reading configuration"
    Testing httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="main" file="httpproxy.c" line="189" message="reading profiles"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_load_list" file="scr_scanner.c" line="1123" message="sc type: 2"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_load_list" file="scr_scanner.c" line="1137" message="failed to load list"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_update" file="scr_scanner.c" line="1214" message="started update thread"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_log" file="scr_scanner.c" line="1114" message="Response status was 400 (Bad Request) instead of 200"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_log" file="scr_scanner.c" line="1114" message="The download function returned a permanent error"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_update_list" file="scr_scanner.c" line="1190" message="failed to download list: 41, status 6"
    httpproxy[8684]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_update_list" file="scr_scanner.c" line="1195" message="serial: SFLX-NSEU-6WFT-2880, perm serial: SFLX-NSEU-6WFT-2880"


    might be a bug in the disk version.  if you have 2 gigs of ram or more try using the mem option.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • i've been running this for days now and the client i have it on has NOT seen any interruptions.  I would have heard about it if there where..[:)]


    Awesome, thanks for the assurance. Turning it on now!
  • I actually have it running on both machines in my sig with only performance benefits to be seen..[:)]

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Any Astaro 8.100 installation, software or hardware, is capable of using this feature eclipse79. 
     

    I know scott [:)] My question was if asg320 has the required ram to properly work. Currently I have a 220, but cause of ram usage, I was thinking to move to 320 or software version... in hardware spec I found no info about ram insalled in 320 [:O]
  • if it's not ram capable you can always use the disk option.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Hi,
    I have noticed my cpu usage has increased from less than 1% to around 5% average. I know small, but might be of interest to those running machines that already have a high cpu use.

    Regards

    Ian M

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.