I have one Astaro, running ASG v7.403. It's a normal desktop-pc with a Pentium 4 (3,2 GHz), and 3 GB RAM (currently, about 35% RAM in use). (single harddrive, no RAID) It never swaps. Nevertheless, it looks like it's sometimes overloaded.
Occasionally, I get the message
Do you want the current request to be aborted?
When that happens, the WebAdmin shows a cpu-load of more than 90%.
I started an ssh-session and launched "atop". Which sometimes shows the CPU-loads in red.
Here's an overview of the configuration:
- This machine has been running since 2005 (or longer)
- 5 physical network interfaces
- almost no remote users (only admins) normally not more than 2 admins logged in at the same time.
- 988 host definitions, 245 service definitions
- 161 packet filter rules
- 2 active Masquerading rules, 31 active NAT rules
- IPS active with 4140 of 7059 patterns
- Watching 1 local network with about 250 nodes
- Anti-DoS/Flooding active: "Use TCP SYN Flood Protection" only
- Anti-Portscan active, action: drop traffic, limit logging
- 11 HTTP Servers, 3 DNS server and 3 SMTP servers registered under IPS / Advanced
- No modified IPS rules
- SMTP proxy active, but no anti-virus or anti-spam. All mails (if any) are cached and forwarded to another machine for filtering. Normally, the dashboard shows: "0 emails processed".
- Web proxy active. 7 HTTP/S profiles + default profile
- VoIP and IM/P2P-Security is off.
- 3 IPSec Site2site VPN-connections, no SSL Site2site-VPN
- 171 local users (used mainly for PPTP-VPN); normally never more than 5 concurrent PPTP-connections
- IPSec VPN, OpenVPN and PPTP deamon log are transmitted to remote syslog server
Statistics for today shows: (it's 16:25 now, working hours are almost over for most employees)
- 53 600 packets filtered
- 4 100 URLs filtered; 287 475 http-requests served today
Is that too much for this machine?
What could I do to substantially reduce the load on the server?
I have 75 packet filter rules for the VPN-users to make sure they can only reach those machines which are needed. Of course, everything else is blocked. Would it help to create some groups under Users / Groups and use these groups for the packet filter rules? I estimate that I could reduce the 75 rules to 25.
If anybody has some more ideas, I'd really appreciate that.
Would it help to replace the normal harddrive with a RAID 0?
Or do I need a faster server?
Hon.
This thread was automatically locked due to age.