We have in the last two weeks, had two instances where WAF would stop serving any requests.
The second time this happened, I had a look at the WAF log, and saw multiple of the following entries:
[mpm_worker:error] [pid 6514:tid 4147865280] AH00288: scoreboard is full, not at MaxRequestWorkers
which would then have the following result (I presume the above error is causing this, since it happens around the same time):
[proxy_http:error] [pid 9394:tid 4025981808] (70007)The timeout specified has expired: [client <external user's IP>] AH01102: error reading status line from remote server <internal IP>, referer: <someurl>
I have seen singular instances of this being referenced on old forums (https://www.astaro.org/gateway-products/web-server-security/55821-9-307-6-waf-scoreboard-error.html), which doesn't offer any other advice than "the hardware is too weak". We use a UTM320, with WAF having served around 3 000 000 requests, totalling around 30Gb today (3.6m, 37.2Gb yesterday). CPU is normally around 50%, with RAM constantly at about 65%.
Any advice?
This thread was automatically locked due to age.