pfilter-reporte is chewing up 100% of cpu for long periods of time resulting in system loads hovering between 1-4. Even as root in console this process won't go away.
This thread was automatically locked due to age.
Hi
Andreas lets get one thing clear, your comments were not helpful, they came out very abrupt and showed Astaro as a company that really does not care a crap about anyone, which I know is not the case.
The prolem William (Please reconsider staying with Astaro, your help on the forums are much appreciated) and others, including me has been reported since 6.908. However I do not feel enough data was gathered for you to fix the issue. IPS has an issue with load, when I say load, I am talking about over 100 concurrent connections within a 1 minute period, eg. Bittorent, Skype, etc. I run 7.002 on a Shuttle XPC, Celeron D 3.33 Ghz, 1 GB DDR RAM, 40 GB HD. Dlink 10/100 530TX. When I run a bittorrent client (from bittorent.com). Even if i just download 1 torrent, Astaro goes nuts, CPU goes to 100% and Webadmin is not responsive. I have to stop the download to get back into Webadmin.
The Astaro config i have is 2 basic rules, 1 internal Network Any Any Allow Log and a cleanup, Any Any Any Drop don't log rule.
IPS Peer to Peer is on, all is set to block except bittorent. If you turn off IPS and re test, my CPU stays below 10%
Andreas, please let me know if there are any logs I can give to help sort this issue out that many members look to be having
It looks like the Astaro box is reporting a portscan from your internal workstation. I can not see a way to stop that as there is no 'Allowed Networks' section to prevent it from 'seeing' this.
Andreas if you are reading this, I would say this is a possible bug / feature request. This is a powerful and needed feature, but I think it needs a way of making it less senseative and to allow exclusions, like an 'Allowed Networks / User / Node' section
It looks like the Astaro box is reporting a portscan from your internal workstation. I can not see a way to stop that as there is no 'Allowed Networks' section to prevent it from 'seeing' this.
Andreas if you are reading this, I would say this is a possible bug / feature request. This is a powerful and needed feature, but I think it needs a way of making it less senseative and to allow exclusions, like an 'Allowed Networks / User / Node' section
top - 20:17:02 up 6 days, 5 min, 1 user, load average: 4.02, 1.87, 0.71
Tasks: 92 total, 1 running, 90 sleeping, 0 stopped, 1 zombie
Cpu(s): 74.5%us, 9.8%sy, 0.0%ni, 0.0%id, 15.7%wa, 0.0%hi, 0.0%si, 0.0%st
Mem: 499996k total, 456908k used, 43088k free, 70140k buffers
Swap: 1052248k total, 68k used, 1052180k free, 93908k cached
Change delay from 1.0 to:
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
19291 root 16 0 26748 7908 3008 S 15.4 1.6 1:23.61 pfilter-reporte
11356 root 16 0 38432 22m 1836 D 15.4 4.7 0:00.16 confd.plx
3176 root 16 0 13332 8432 2496 S 2.9 1.7 52:35.38 selfmonng.plx
11355 root 15 0 38576 23m 1980 D 2.9 4.7 0:00.20 confd.plx
19301 root 15 0 12968 8080 2492 S 1.9 1.6 0:03.01 notifier.plx