We have 2 x ASG320's in ACTIVE/ACTIVE configuration.
We are seeing performance bottlenecks, pretty much 100% CPU on the master, whilst relatively low (25%) on the secondary machine. Users are complaining that web sites are slow to respond / timing out etc. Bandwidth is not an issue for us.
When we scan the web filtering logs, we see that that 60-70% of all requests go via the master, whilst the remainder is via the slave. We have noticed that a ridiculous amount of CPU seems to be given over to running "inline" reports, "snort" (even though we have IDS switched off), "mysqld", "websec-reporter" etc. It seems that the core management functionality / reporting is strangling performance.
The obvious point here is that it would be a great advantage to prioritise the slave box for handling the web content filtering, is there any way to achieve this? We are currently running firmware 7.104 and have 1.1 Million entries in our http.log on a typical day (predomaintely 9-5).
We are at a point whereby we need to further upscale by increasing the cluster, but given the state of how load is distributed in a cluster this seems like a questionable strategy.
Jason.
This thread was automatically locked due to age.